Talk With an Expert

Importance of Defining Security Functions to Obtain Visibility in Assets From Level1 of the Purdue Model

Importance of Defining Security Functions to Obtain Visibility in Assets From Level1 of the Purdue Model (PDF, 0.56MB)Published: 15 Dec, 2022
Created by:
Michael HoffmanGloria Cedillo
Alejandro Cadena, Michael Hoffman & Gloria Cedillo

For years many practitioners in the ICS security community realized that guidelines and best practices around secure PLC programming practices were lacking. To address this problem, ICS security professionals in the community pulled together to develop the Top 20 PLC controls. Beyond these controls, however, it is essential to define abnormality detections to display the information on the HMI clients. This allows operations staff to respond to an incident at an early stage and provides the capability to forward the same information to SIEM systems for further analysis. These functions can be developed by using the PLC’s own capabilities and adding operational conditions that infer cyber events.

Meet the experts