cyber security evaluation tool (cset ) version...

32
Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems Cyber Emergency Response Team (ICS-CERT)

Upload: others

Post on 03-Jul-2020

21 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Cyber Security Evaluation Tool

(CSET ) Version 6.2

Industrial Control Systems Cyber Emergency Response

Team (ICS-CERT)

Page 2: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

DHS NCCIC and ICS-CERT CSET

DHS CSET 6.2 Tool

• NIST Cybersecurity Framework

• NIST 800-30

• NIST 800-53 Rev 3

• NIST 800-53 Rev 4

• NIST 800-82 Rev 2

• NIST 1108

• NISTR 7628

• NERC CIP

• More!

National Cybersecurity and

Communications Integration Center

http://www.us-cert.gov/nccic/

Page 3: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

• Stand-alone Software application

• Self-assessment using recognized standards

• Tool for integrating cybersecurity into existing corporate risk management strategy

CSET Download:

www.ics-cert.us-cert.gov/Downloading-and-Installing-CSET

DHS CSET

Page 4: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Organize the TeamSelect the

Mode and

Standards

Determine

the Security

Assurance

Level

Build the

Network

Diagram

Answer

Questions

Analyze

Results

Assessment Process

Page 5: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Assessment Process

A TEAM of participants is required

to perform a successful assessment

Type of Participant KnowledgeControl Systems Engineer Control systems

Configuration Manager Systems management

Operations Manager Business operations

IT Network Specialist IT infrastructure

IT Security Officer Policies & procedures

Risk Analyst or Insurance Specialist Risk

Page 6: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

CSET Home

Page 7: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Video Tutorials (YouTube)

Page 8: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Resource Library

Page 9: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

New Assessment Form

Page 10: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Standards Home - Step 1 Assessment Mode

Page 11: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Step 2 - Questions and Standards

Page 12: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Step 3 - Security Assurance Level

Page 13: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Step 3 – General SAL

Page 14: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Step 3 - NIST SAL

Page 15: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

NIST SAL Impact Levels

Page 16: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

NIST Step 2 Information Types

Page 17: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

CNNSI SAL

Page 18: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

NIST Step 3 Questions

Page 19: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Diagram – Tools, Templates, Inventory

Page 20: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Diagram – Tools, Templates, Inventory

Page 21: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Diagram – Zones, Layers

Page 22: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Diagram – Components

Page 23: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Questions – Family, Detail, Info

Page 24: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Analysis - Dashboard

Page 25: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Analysis Detail

Page 26: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Analysis Detail

Page 27: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Reports

Page 28: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

System Security Plan

Page 29: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Use Multiple Assessments

Page 30: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Add Assessments

Page 31: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Trending

Page 32: Cyber Security Evaluation Tool (CSET ) Version 6sites.nationalacademies.org/cs/groups/depssite/... · Cyber Security Evaluation Tool (CSET ) Version 6.2 Industrial Control Systems

Compare

Sort By Best Sort By Worst

Site Total Questions Answered Yes No

Site A 560 300 260

Site B 342 300 42

Site C 268 152 116