sicherheit im produktlebenszyklusfiles.messe.de/abstracts/58541_1104_1200_schierholz_abb.pdf ·...

12
Sicherheit im Produktlebenszyklus Von der Wiege bis zur Bahre Dr. Ragnar Schierholz, Hannover Messe Thementag Industrial IT Security, 2014-04-11

Upload: others

Post on 12-Jul-2020

10 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Sicherheit im Produktlebenszyklusfiles.messe.de/abstracts/58541_1104_1200_Schierholz_ABB.pdf · Secure Development Lifecycle Example: Validation of Security Updates Microsoft security

Sicherheit im ProduktlebenszyklusVon der Wiege bis zur Bahre

Dr. Ragnar Schierholz, Hannover Messe – Thementag Industrial IT Security, 2014-04-11

Page 2: Sicherheit im Produktlebenszyklusfiles.messe.de/abstracts/58541_1104_1200_Schierholz_ABB.pdf · Secure Development Lifecycle Example: Validation of Security Updates Microsoft security

Life cycle aspects of cyber security for ICS

PS: Product Supplier

SI: System Integrator

AO: Asset Owner

Draft material from IEC 62443*

April 11, 2014 | Slide 2

© ABB Group

* Based on VDI 2182

Page 3: Sicherheit im Produktlebenszyklusfiles.messe.de/abstracts/58541_1104_1200_Schierholz_ABB.pdf · Secure Development Lifecycle Example: Validation of Security Updates Microsoft security

Life cycle aspects of cyber security for ICS

PS: Product Supplier

SI: System Integrator

AO: Asset Owner

Draft material from IEC 62443

April 11, 2014 | Slide 3

© ABB Group

Page 4: Sicherheit im Produktlebenszyklusfiles.messe.de/abstracts/58541_1104_1200_Schierholz_ABB.pdf · Secure Development Lifecycle Example: Validation of Security Updates Microsoft security

How ABB works with Cyber Security An important factor in all phases

Design

Implementation

Verification

Release

Support

Design

Engineering

FAT

Commissioning

SAT

Operation

Maintenance

Review

Upgrade

Product

Lifecycle

Project

LifecyclePlant Lifecycle

April 11, 2014 | Slide 3

© ABB Group

Page 5: Sicherheit im Produktlebenszyklusfiles.messe.de/abstracts/58541_1104_1200_Schierholz_ABB.pdf · Secure Development Lifecycle Example: Validation of Security Updates Microsoft security

How ABB works with Cyber SecurityAn integral part of ABB’s products and systems

April 11, 2014 | Slide 3

© ABB Group

Page 6: Sicherheit im Produktlebenszyklusfiles.messe.de/abstracts/58541_1104_1200_Schierholz_ABB.pdf · Secure Development Lifecycle Example: Validation of Security Updates Microsoft security

Security Development LifecycleThe Process

Training Requirements Design Implementation Verification Release Response

Core training Define quality

gates/bug bar

Analyze cyber

security risk

Attack surface

analysis

Threat modeling

Specify tools

Enforce banned

functions

Static analysis

Dynamic/Fuzz

testing (e.g.

DSAC)

Verify treat

models/attack

surface

Response plan

Final security

review (FSR)

Release archive

Execute

response plan

(e.g. vulnerability

handling policy)

Administer and

track security

training

Education

Guide product

teams to meet

SDL

requirements

Process

Establish release

criteria and sign-

off as part of G5

Accountability

Incident

response

April 11, 2014 | Slide 3

© ABB Group

Page 7: Sicherheit im Produktlebenszyklusfiles.messe.de/abstracts/58541_1104_1200_Schierholz_ABB.pdf · Secure Development Lifecycle Example: Validation of Security Updates Microsoft security

Security Development LifecycleExample: Verification

April 11, 2014 | Slide 7

© ABB Group

Formally established, centralized and independent security

test center

Leveraging state-of-the-art open source, commercial and

proprietary robustness and vulnerability analysis tools

Close collaboration with ABB developers providing in-depth

analysis and recommendations

Page 8: Sicherheit im Produktlebenszyklusfiles.messe.de/abstracts/58541_1104_1200_Schierholz_ABB.pdf · Secure Development Lifecycle Example: Validation of Security Updates Microsoft security

Secure Development LifecycleExample: Validation of Security Updates

Accreditation of Anti-virus SW for Sentinel Users

McAfee VirusScan® Enterprise with ePO Server and

Symantec Endpoint Protection

Configuration guidelines

Verified in system tests

Node based or centralized management

Updating via server in the Demilitarized zone

Daily verification of Definition files

Update production systems with 48h delay

Redistribution of Symantec definition files

April 11, 2014 | Slide 3

© ABB Group

Page 9: Sicherheit im Produktlebenszyklusfiles.messe.de/abstracts/58541_1104_1200_Schierholz_ABB.pdf · Secure Development Lifecycle Example: Validation of Security Updates Microsoft security

Secure Development LifecycleExample: Validation of Security Updates

Microsoft security updates for Sentinel Users

All relevant updates are tested for compatibility

Result published typically within 3 – 7 days

Other 3rd party SW (e.g. Adobe Reader)

Validated with next Microsoft Security Update

Deployment

The System 800xA Qualified Security Updates

For node by node deployment

MS Security Updates delivered from ABB

WSUS for centralized management

April 11, 2014 | Slide 3

© ABB Group

Page 10: Sicherheit im Produktlebenszyklusfiles.messe.de/abstracts/58541_1104_1200_Schierholz_ABB.pdf · Secure Development Lifecycle Example: Validation of Security Updates Microsoft security

Security Development Lifecycle

In case you want to be informed of vulnerabilities found in

ABB products:

Public disclosure on www.abb.com/cybersecurity and ICS-

CERT

In case you have found a vulnerability in our products:

Use the “Contact us” feature on ABB’s Cyber security

webpage www.abb.com/cybersecurity to report any

security issue

Example: Vulnerability handling

April 11, 2014 | Slide 10

© ABB Group

Page 11: Sicherheit im Produktlebenszyklusfiles.messe.de/abstracts/58541_1104_1200_Schierholz_ABB.pdf · Secure Development Lifecycle Example: Validation of Security Updates Microsoft security

Contact

Cyber Security Analyst

ABB AG

Schillerstr. 72

DE-32425 Minden

Phone +49 517 830 1080

Mobile +49 171 189 2349

E-Mail [email protected]

Dr. Ragnar Schierholz

Page 12: Sicherheit im Produktlebenszyklusfiles.messe.de/abstracts/58541_1104_1200_Schierholz_ABB.pdf · Secure Development Lifecycle Example: Validation of Security Updates Microsoft security