ISA SP99 Introduction: Manufacturing and Control Systems Security - PowerPoint PPT Presentation

1 / 9
About This Presentation
Title:

ISA SP99 Introduction: Manufacturing and Control Systems Security

Description:

ISA SP-99 Chairman. ISA SP-99 Overview. Dispelling the Myths About Control Systems Security. Myth 1: Security is a Technology Issue, not a Business Issue ... – PowerPoint PPT presentation

Number of Views:140
Avg rating:3.0/5.0
Slides: 10
Provided by: bobw173
Category:

less

Transcript and Presenter's Notes

Title: ISA SP99 Introduction: Manufacturing and Control Systems Security


1
ISA SP-99 Introduction Manufacturing and
Control Systems Security
  • Bryan L Singerbryan_singer_at_entegreat.com
  • ISA SP-99 Chairman

2
ISA SP-99 Overview
3
Dispelling the Myths About Control Systems
Security
  • Myth 1 Security is a Technology Issue, not a
    Business Issue
  • Myth 2 Control Systems arent Likely Targets
  • Myth 3 Most Threats are from Hactivists or
    Script Kiddies bent only on Defacing Websites
  • Myth 4 We are secure We Have a Firewall

4
ISA SP-99 Purpose
  • Communicate the Need for Manufacturing and
    Control Systems Security and Defeat Common
    Myths
  • Provide users with the tools necessary to
    integrate a comprehensive security process for
    Manufacturing and Control Systems into a larger
    Corporate Information Security Plan
  • Assist users in evaluating, selecting, and
    applying both technological and process based
    security measures
  • Provide the means for self-evaluation and
    performance based metrics to continually assess
    and improve security practices and keep pace with
    the ever changing threats

5
Why Do We Need Another Standard?
  • There are no currently published standards
    specifically addressing manufacturing and control
    systems security issues
  • Common methods and practices acceptable for
    Information Systems have been shown wanting in
    terms of control systems
  • ISA committees for SP-67, 84, 95 and others have
    recognized the need to address electronic
    security

6
ISA SP-99 What Should it Cover?
  • Recommended processes and procedures should be
    specified in terms of an overall corporate
    security process, whether one exists or not
  • Proper selection of technology and means of
    application to control systems security
  • Flexible guidelines that can easily be adopted
    into existing business models
  • Tools to assist users in selecting metrics to
    evaluate performance.

7
ISA SP-99 What Should it Not Cover?
  • Areas of specific overlap with other ISO/ISA/IEEE
    standards
  • Technology or Vendor Specific Recommendations
  • Sector specific language content

8
Future Direction
  • Establish Working Committee for ISA
  • Create Technical Report by July 2003
  • Continue Standards Development Process

9
Discussion
  • QA
  • Thanks!
Write a Comment
User Comments (0)
About PowerShow.com