ICS Cyber Security Use Case #1 - What would you do about default passwords

Aug. 30, 2010

I continue to be reminded there has been too much discussion on problems and not enough on solutions (even though we keep finding new problems).  What seems obvious to me may not seem as obvious to others. To address those concerns, I will provide a series of ICS cyber security use cases to get your feedback on how you would address these actual cases. 

I continue to be reminded there has been too much discussion on problems and not enough on solutions (even though we keep finding new problems).  What seems obvious to me may not seem as obvious to others. To address those concerns, I will provide a series of ICS cyber security use cases to get your feedback on how you would address these actual cases. 

Use case 1 – Default passwords. There are reasons for keeping default passwords (rarely changed changed passwords generally known to many users) in an ICS.  However, IT security policy and the NERC CIPs require default passwords to be changed to “strong” passwords and changed periodically. In a benign office environment, this won’t cause unacceptable conditions. In an industrial setting such as a power plant, this can also be acceptable during normal operation. However, during an upset condition when personnel are under high stress, trying to remember whether a slash is forward or backward can be a real problem especially if there isn’t a “yellow sticky” on the computer screen which in itself is a security problem. One possibility of addressing the default password issue would be the use of biometrics. How would you address the default password issue in an operational environment without adversely impacting the safe and reliable operation of the facility?

Joe Weiss

Sponsored Recommendations

Make Effortless HMI and PLC Modifications from Anywhere

The tiny EZminiWiFi is a godsend for the plant maintenance engineers who need to make a minor modification to the HMI program or, for that matter, the PLC program. It's very easy...

The Benefits of Using American-Made Automation Products

Discover the benefits of American-made automation products, including stable pricing, faster delivery, and innovative features tailored to real-world applications. With superior...

50 Years of Automation Innovation and What to Expect Next

Over the past 50 years, the automation technology landscape has changed dramatically, but many of the underlying industry needs remain unchanged. To learn more about what’s changed...

Manufacturing Marvels Highlights Why EZAutomation Is a Force to Be Reckoned With

Watch EZAutomation's recent feature on the popular FOX Network series "Manufacturing Marvels" and discover what makes them a force to be reckoned with in industrial automation...