What are DHS’s industrial control system cyber security priorities?

Feb. 1, 2011

It seems that while ignoring hard problems such as Stuxnet, DHS NCSD is focusing on the easy things such as reinventing roadmaps. Why hasn’t DHS provided more information on Stuxnet since September yet Controls Magazine has provided the latest information on the PLC issues in this month’s issue?  What is DHS doing about the details provided by Ralph Langner? What is DHS doing about other field controller issues? These are hard problems.

It seems that while ignoring hard problems such as Stuxnet, DHS NCSD is focusing on the easy things such as reinventing roadmaps. Why hasn’t DHS provided more information on Stuxnet since September yet Controls Magazine has provided the latest information on the PLC issues in this month’s issue?  What is DHS doing about the details provided by Ralph Langner? What is DHS doing about other field controller issues? These are hard problems.
Process control systems, networks, and protocols in fossil plants, chemical plants, water systems, and even nuclear plants are similar enough that NIST prepared NIST SP800-82 for all industries and ISA created S99 for all industries. Why did DHS consider it necessary to create multiple roadmaps for different industries that all use similar control systems with similar communication protocols? These are easy problems. Why is DHS ready to develop a nuclear plant R&D roadmap?  As a nuclear engineer I am very curious.
DHS S&T funded the Conficker Working Group. The report makes no mention of the NERC Conficker Advisory or control systems. This is important because control systems have been affected by Conficker and Stuxnet can utilize downadup (Conficker) as a delivery vehicle. There is little DHS S&T work on controllers (non-Windows parts of the system) and no mention of industrial controllers (other then the general term “control systems”) in the recent DHS S&T Cyber Security BAA announcement.
Are we making progress?
Joe Weiss

Prior to psting this blog I e-mailed both DHS NCSD and DHS S&T for comment and neither has responded

Sponsored Recommendations

Make Effortless HMI and PLC Modifications from Anywhere

The tiny EZminiWiFi is a godsend for the plant maintenance engineers who need to make a minor modification to the HMI program or, for that matter, the PLC program. It's very easy...

The Benefits of Using American-Made Automation Products

Discover the benefits of American-made automation products, including stable pricing, faster delivery, and innovative features tailored to real-world applications. With superior...

50 Years of Automation Innovation and What to Expect Next

Over the past 50 years, the automation technology landscape has changed dramatically, but many of the underlying industry needs remain unchanged. To learn more about what’s changed...

Manufacturing Marvels Highlights Why EZAutomation Is a Force to Be Reckoned With

Watch EZAutomation's recent feature on the popular FOX Network series "Manufacturing Marvels" and discover what makes them a force to be reckoned with in industrial automation...