Modern cyber threats increasingly target operational technology (OT) systems, prompting a necessity for organizations to take proactive measures. Many IT operators recognize the importance of isolating critical infrastructure during crises, but many don't know how to implement this strategy effectively. To address this gap, the Cybersecurity and Infrastructure Security Agency (CISA), alongside Five Eyes agencies from the US, UK, Australia, Canada, and New Zealand, has released a detailed action plan titled CI Fortify. This guide aims to help organizations preserve their vital systems against cyber threats while ensuring a safe recovery post-incident.
“The end state must be to enable the continued operation of critical services in a state of isolation,” the guide stresses, underscoring the importance of maintaining vital functions even when faced with potential attacks.
A Six-Step Framework for System Isolation
The guide lays out a structured approach, detailing six actionable steps organizations can take to isolate their systems effectively:
- Identify vital systems and networks
- Recognize critical customers
- Establish common levels of criticality and trust for networks and hosts
- Map potential isolation points and connections
- Design effective separation and isolation points
- Create and test an isolation strategy
The first two steps require identifying the essential systems necessary for maintaining crucial services, alongside establishing delivery benchmarks based on the needs of key customers. For example, relevant metrics could include the volume of power or water required to keep operations running efficiently.
To assess criticality levels, organizations should segment networks, hosts, and systems into zones according to their role and susceptibility to threats. Employing risk management practices will facilitate this classification process.
Once systems are categorized, the next phase involves mapping interconnections between those critical networks and other systems. It's vital to track connections with vendors that have remote access, cloud environments, and peer networks, among others. Each connection could impact both security posture and operational resilience, making this mapping essential.
In analyzing these connections, operators should also understand the significance of the data flowing through them and how critical they are to operations. Comprehensive documentation is necessary, capturing technical aspects such as architectural diagrams, firewall settings, and emergency contact details.
The guide asserts, “This critical technical information will be necessary for building isolation controls.”
Creating Effective Isolation Points
While the concept of zero-trust networks suggests that systems inherently distrust one another, the guide highlights the need for deliberate isolation points. These points can significantly limit the potential impact of cyber incidents by containing threats and accelerating recovery efforts. “Organizations must build physical isolation points into their vital systems,” the guidelines emphasize.
Achieving isolation necessitates eliminating connectivity with non-OT networks, preventing information exchange through shared infrastructure. Critical resources, such as power and cooling, should not be accessible from non-secure networks. Organizations should enhance OT boundaries by ensuring the full segregation of management and administrative systems, thereby protecting network control planes as best as possible.
For organizations with large, diverse infrastructures, complete physical isolation might not be feasible. In cases where third-party communication is essential, securing OT boundaries with strong encryption will be vital. Reliable communication paths, such as dedicated wavelengths or fiber pairings, can help maintain data security without vulnerability.
Understanding Dependencies and Isolating Gradually
Operators need to grasp the interdependencies between OT and non-OT systems. Issues may arise from shared routing, storage, and related services, underscoring the need for careful consideration before any physical isolation occurs. An understanding of these interactions will prevent any unintended loss of performance or service integrity.
Extended separation poses its own set of risks, including the potential for reduced visibility and compliance lapses. Thus, the guide recommends a phased approach to isolation, allowing organizations to adjust progressively whilst maintaining critical operations.
Organizations should consider these steps in order to fortify their OT systems:
- Restrict remote access to OT systems via intermediaries for remote workers;
- Curb on-premises remote access from corporate networks;
- Isolate all connections between OT and non-OT environments;
- Limit connections between decentralized OT systems;
- Fully isolate OT environments and essential systems.
“Progressively removing access to OT systems as the cyber threat environment deteriorates may be effective in halting or hindering attacks on vital OT and enabling systems,” the guide concludes, offering a pragmatic pathway for organizations to enhance their cybersecurity posture within the OT realm.