Detecting and Protecting Against Data Integrity Attacks in Industrial Control System Environments

Current Status

The National Cybersecurity Center of Excellence (NCCoE) recently released draft project description Detecting and Protecting Against Data Integrity Attacks in Industrial Control System Environments

The public comment period for the draft closed on July 25, 2019. If you have questions or suggestions, please email us at manufacturing_nccoe@nist.gov.

Summary

Manufacturing organizations relying on industrial control systems (ICS), which monitor and control physical processes that produce goods for public consumption, are facing an increasing number of cyber attacks. As manufacturing organizations continue to converge information technology with operational technology to promote corporate business systems’ connectivity and remote access capabilities, they become more vulnerable to cybersecurity threats. Threats to manufacturing environments such as destructive malware, malicious insider activity, and even honest mistakes create the imperative for manufacturing organizations to strengthen protection of their ICS.

The NCCoE is proposing a project to provide a practical example solution to help manufacturers protect their ICS from data integrity attacks.

The NCCoE project team will leverage the National Institute of Standards and Technology (NIST) Engineering Laboratory to provide a comprehensive approach that manufacturing organizations can use to address the challenge of protecting ICS against data integrity attacks by leveraging the following cybersecurity capabilities: behavioral anomaly detection, security incident and event monitoring, ICS application white-listing, malware detection and mitigation, change control management, user authentication and authorization, access control least privilege, and file-integrity checking mechanisms.

 This project will result in a publicly available NIST Cybersecurity Practice Guide, a detailed implementation guide of the practical steps needed to implement the cybersecurity reference design that addresses this challenge.

Questions? Comments? Reach us at manufacturing_nccoe@nist.gov.

Join Our Community of Interest

Interested in joining the Detecting and Protecting Against Data Integrity Attacks in Industrial Control System Environments Community of Interest? Contact us!

A Community of Interest is a group of professionals and technical advisors convened to support the cybersecurity resiliency of the U.S. economy. Read More.