How to Secure OT Applications Beyond the Perimeter

601 views
β€’
May 29, 2024
by
RSAC Cybersecurity
YouTube video player
How to Secure OT Applications Beyond the Perimeter

TL;DR

Protect OT applications with zero trust, role-based access control, trusted devices, and identity integration instead of relying solely on isolation or perimeter defenses. Define permissions by job and location, bind controllers to the approved FactoryTalk Directory, restrict unnecessary network paths, secure engineering workstations, and continuously monitor changes so unauthorized activity can be detected and addressed.

Transcript

Listeners, and welcome to this installment of our RSAC 365 webcast series. I'm your host, Tatiana Sanchez. This month, we are focusing on application security, and today we are excited to be joined by Diane Golden, who will discuss how application security principles intersect with the operational technology landscape. Before we dive in today's top... Read More

Key Insights

  • OT isolation is not a sufficient security strategy because malware has successfully crossed air gaps, while operational requirements increasingly demand connections between industrial systems and other environments. OT applications therefore need defenses that protect the systems themselves instead of depending only on a network perimeter.
  • Connecting IT and OT systems creates operational value by making industrial data available for better resource use, production optimization, reduced energy costs, predictive maintenance, and downtime prevention. The same connectivity introduces paths through which external attackers may enter IT systems and pivot toward operational assets.
  • OT access control is based on identifying who can access each system, who should have access, and which actions each person should perform. Role-based access control should grant enough authority for users to complete their jobs without providing unnecessary permissions across machines, applications, or facilities.
  • Location-based authorization is important because an operator responsible for one plant area should not automatically receive access to the entire facility. Enterprise engineering teams may legitimately require permissions across several sites, but broader access should reflect actual responsibilities rather than administrative convenience.
  • FactoryTalk Directory functions as a central source for detailed OT security mappings, while integrating with identity providers such as Active Directory. It can evaluate a user’s groups, assigned permissions, and workstation identity before authorizing activities involving FactoryTalk software and industrial devices.
  • Modern identity integration is available through Azure Active Directory or an on-premises OpenID Connect provider, including authenticator application-based multifactor authentication options. OT vendors generally should integrate with an organization’s preferred identity provider so access can be managed consistently and removed more easily when someone leaves.
  • Security authority binding connects a PLC program to the authorized FactoryTalk Directory. A secured controller can therefore reject interaction from someone using a different directory in which they granted themselves unrestricted privileges, strengthening the practical enforcement of role-based access policies at the device level.
  • Trusted slots harden controllers that connect to multiple networks by limiting where sensitive interactions may originate. A network serving downstream sensors, actuators, or other field devices should not be able to reprogram a PLC when those devices have no legitimate reason to perform programming operations.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why is perimeter security insufficient for OT applications?

Perimeter security is insufficient because OT systems cannot safely assume they are completely isolated. Malware has crossed air gaps and reached industrial systems, while organizations increasingly connect operational environments to obtain data for resource efficiency, production optimization, lower energy costs, predictive maintenance, and downtime prevention. A zero trust approach gives OT systems their own protective controls instead of making the firewall or air gap the only meaningful defense.

Q: How should role-based access control be designed for OT systems?

OT role-based access control should begin with observing and documenting what administrators, engineers, operators, view-only users, and other personnel actually need to do. Permissions can then be mapped to job functions such as changing security roles, administering backup schedules, modifying programs, or operating an HMI. The goal is least privilege without preventing legitimate work, with additional location restrictions when users only support particular plant areas.

Q: What is the role of FactoryTalk Directory in OT security?

FactoryTalk Directory provides the central mappings that determine which users and computers may perform specific actions in a FactoryTalk environment. It integrates with an identity provider such as Active Directory, but retains detailed industrial context, including permission to update firmware, download programs, make controller edits, or alter backup schedules. Because it governs sensitive authorization decisions, the directory itself should be protected, secured, and appropriately isolated.

Q: How does FactoryTalk Security verify an engineering user?

An engineer first signs into a domain-joined engineering workstation with domain credentials. When the engineer opens FactoryTalk-based software, FactoryTalk Directory can use its link to Active Directory to evaluate the user’s group memberships. It can also verify that the workstation is a recognized device in the directory. The requested controller interaction proceeds only when the user, computer, assigned role, and requested function satisfy the configured authorization policy.

Q: How can modern identity providers and MFA support OT access?

A FactoryTalk environment can integrate with Azure Active Directory or an on-premises OpenID Connect provider to use more modern identity capabilities, including authenticator application-based multifactor authentication. The preferred model is for the OT platform to connect with the organization’s chosen identity provider rather than become a separate identity system. This creates more seamless security mappings and makes it easier to disable operational access when a person leaves the organization.

Q: What OT actions should receive fine-grained authorization?

Fine-grained authorization should cover sensitive activities such as updating device firmware, going online with a controller, making online edits, downloading programs, and modifying disaster recovery backup schedules. Operators may need to sign into an HMI and interact with a machine without receiving access to the engineering development environment. Administrators can control role mappings, while engineers receive only the programming capabilities required for their assigned responsibilities.

Q: What is security authority binding for a PLC?

Security authority binding embeds an association in the PLC program that identifies the FactoryTalk Directory containing the approved access-control mappings. It is comparable to joining a workstation to a domain. When the controller is secured, it can reject a person who arrives with another FactoryTalk Directory that grants unrestricted access, because that person is not authenticated through the authority trusted by the controller.

Q: How do trusted slots help harden an OT controller?

Trusted slots help restrict sensitive controller interactions when a PLC connects to multiple networks. For example, a network connected to downstream sensors, actuators, or other field devices normally has no legitimate reason to reprogram the PLC. Configuring trust around the appropriate controller connections reduces the opportunity for programming activity to originate from networks whose attached devices should only support their intended operational functions.

Summary & Key Takeaways

  • OT systems can no longer depend on isolation as their primary defense because malware can cross air gaps and organizations increasingly need operational data for production optimization, energy reduction, environmental efficiency, predictive maintenance, and downtime prevention. Connecting IT and OT creates value, but it also exposes industrial applications to external attackers, mistakes, and malicious insiders.

  • Effective OT identity and access management begins by determining who needs access, which operations each person requires, and where those permissions should apply. FactoryTalk Security can connect with an organization’s identity provider while maintaining detailed OT permissions for firmware updates, program downloads, controller edits, and backup administration. Access should remain sufficient for each job, but no broader.

  • Controller protection extends beyond user authentication. Security authority binding associates a PLC program with the approved FactoryTalk Directory, preventing someone from using a separate directory that grants unauthorized privileges. Trusted slots can further harden systems by restricting which controller network connections may perform sensitive activities. Secure workstations, change monitoring, and anomaly response complete the broader application-security approach.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š