Group Purchasing
Group Purchasing

ICS Asset Identification: It's More Than Just Security

ICS Asset Identification: It's More Than Just Security (PDF, 3.88MB)Published: 24 Jun, 2020
Created by:
Mark Bristow
Mark Bristow

ICS Asset Identification: It's More Than Just Security, a SANS whitepaper published by SANS Institute in June 2020, explains how organizations can build and maintain an accurate inventory of assets on their industrial control system (ICS) network, and how that inventory supports far more than cybersecurity. The guide covers the four core asset identification techniques, how to bootstrap a program with limited resources, and how to justify the investment to business and board leadership.

Key findings:

  • Asset identification was the No. 1 concern cited by 338 ICS security professionals in the SANS 2019 State of OT/ICS Cybersecurity Survey
  • More than half of ICS operators report spending 20 to 80% of their time just finding and validating plant information, according to industry research cited in the guide
  • ICS asset identification techniques fall into four categories, physical inspection, passive discovery, configuration analysis, and active discovery, each with different tradeoffs in cost, coverage, and scalability
  • Physical inspection, tracing every cable and connection point, produces the most comprehensive initial inventory but is the most labor-intensive and costly method
  • Passive discovery works well for identifying assets at Purdue Model Level 2 and above, but often misses field devices, report-by-exception equipment, and devices hidden behind network address translation
  • Configuration analysis can scale across an entire plant using just a few staff hours by compiling and normalizing existing configuration data, though it reflects a snapshot in time and won't reveal unauthorized "rogue" devices
  • Active discovery can identify otherwise dormant devices, but it can cause older, non-compliant ICS equipment to lock up or exhaust CPU resources, so SANS recommends testing it on representative equipment before production use
  • Mature asset identification programs combine multiple techniques rather than relying on a single method, since no single approach produces a complete inventory on its own
  • Comprehensive asset inventories directly reduce mean time to recovery (MTTR) and are a prerequisite for Failure Modes and Effects Analysis (FMEA), Hazard and Operability Analysis (HAZOP), and Probabilistic Risk Assessments (PRA)
  • Asset identification is described as a foundational precursor to every phase of the NIST Cybersecurity Framework, protect, detect, respond, and recover, since none of those functions can be executed accurately without knowing what assets exist
  • Free and open source tools such as GRASSMARLIN, CyberLens, and Snipe-IT can help bootstrap an asset identification program before an organization commits to commercial solutions

The guide's central argument is that asset identification is usually pitched as a pure security initiative, which undersells its value. The same inventory data that supports cybersecurity also reduces recovery time, informs failure and safety analysis, and lowers regulatory and insurance risk, giving security teams a stronger business case for investment than a security-only pitch would provide. Programs succeed by starting small, using existing documentation and free tools first, and layering in automated methods only as the program matures.

This SANS whitepaper was written by Mark Bristow, SANS Principal Instructor for ICS515: ICS Visibility, Detection, and Response and former Chief of DHS's ICS Cyber Emergency Response Team (ICS-CERT). It was sponsored by Cisco, Palo Alto Networks, PAS, and Tenable.

FAQ

Meet the expert

Mark Bristow
Mark Bristow

Mark Bristow

Principal Instructor

Mark loves the ever-changing landscape of security and views it as a puzzle that must be solved. He especially loves the challenges in ICS security, where the cyber meets the physical. There is no greater success than a safe and effective process.

Read more about Mark Bristow