Designing an Industrial Cybersecurity Program for an Operational Technology Group

1Citations
Citations of this article
24Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The design of a cybersecurity program for an Information Technology ("IT") group is well documented by a variety of international standards, such as those provided by the U.S. National Institute of Standards and Technology ("NIST") 800-series Special Publications ("SP 800"). However, for those wishing to apply standard information security practices in an Operational Technology ("OT") environment that supports industrial control and support systems, guidance is seemingly sparse. This project expands on the abstract concepts described in textbooks by documenting the implementation of an industrial cybersecurity program for a local manufacturing firm. The project started with hardware and software asset inventories, followed by a risk assessment and gap analysis, and then implemented mitigating controls using a combination of manual and automated procedures. Security posture of the OT group was constantly evaluated against corporate security goals, the project-generated risk assessment, and NIST SP 800-171 requirements. Improvements in security posture and compliance to corporate requirements were achieved in part through alignment with existing policies and procedures developed by the organization's IT group, with the balance implemented and documented by the author of this project. The materials generated by this project may be used to assist other organizations starting their journey towards securing their industrial control assets.

Cite

CITATION STYLE

APA

Sell, M., & Dupuis, M. (2023). Designing an Industrial Cybersecurity Program for an Operational Technology Group. In SIGITE 2023 - Proceedings of the 24th Annual Conference on Information Technology Education (pp. 125–130). Association for Computing Machinery, Inc. https://doi.org/10.1145/3585059.3611438

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free