IoT Audits Loom Large in a Connected World

The proliferation of Internet of Things devices is well-documented, with the potential for more than 20 billion connected things by 2020. Installations of connected devices are spanning virtually all industries and cover just about any use case that can be imagined.

With such an enormous volume of connected devices and minimal regulation, it comes as little surprise that many of them have been programmed incorrectly and are supplying users with false or misleading information.

“So, how do you look at scenarios like that?,” said ISACA board director R.V. Raghu during Wednesday’s session on IoT audits at EuroCACS in Edinburgh, Scotland. “It can become very dangerous.”

IoT audits should align with enterprise needs and ensure a compliance approach is factored in from the outset. Auditing IoT can help address a wide array of important questions, including each of the following:

  • How will the device be used from a business perspective, and what business value is expected?
  • What threats are anticipated, and how will they be mitigated?
  • Who will have access to the device, and how will their identities be established and proven?
  • What is the process for updating the device in the event of an attack or vulnerability?
  • Who is responsible for monitoring new attacks or vulnerabilities pertaining to the device?
  • With whom will the data be shared?

In the case of IoT, the answers to these questions can have urgent implications. Raghu used a nuclear plant as an example, saying that the capacity to interpret accurate data in timely fashion can guard against potentially damaging irregularities at the plant.

“We want to be able to pick up the data at the right point and then tell you, this is what we need to do,” Raghu said.

Privacy considerations need to be taken into account by IoT device manufacturers, given the enormous capacity to gather data. Encryption might need to be built into devices to protect potentially sensitive information, such as with medical devices used by hospitals.

“Do we need to get greedy and collect everything that is possible, or do we only collect the data that makes sense to us?” Raghu said. “And, in the post-GDPR world, that is a very important question to ask.”

Raghu also expressed concern that regulation of IoT devices is lagging behind the surging usage, meaning there is little standardization on the IoT landscape.

That puts even more of a premium on strong risk management and robust controls. Among the baseline controls that should be put in place for IoT devices are identity and access management, malware protection, transmission confidentiality and time-stamping. Raghu also highlighted “Level 2” controls, such as patching, vulnerability management and log management, saying many organizations do a subpar job with their log management.

“People don’t want to do the log analysis, and if you don’t do the log analysis, you don’t understand how the device is behaving, and you could have a serious problem on your hands at some point,” Raghu said.

Whether affecting security in homes, in hospitals, in cities’ critical infrastructure or just about any other setting of today’s society, the ramifications of insufficient IoT security can be serious. Raghu said IoT audits should emphasize the importance of continuous monitoring, as prescribing fixes months after the fact can be far too late.

“You don’t have that kind of luxury here,” Raghu said. “You might need to fix it on an ongoing basis, on the fly, so it becomes very important you have a real-time status on this.”

[ISACA Now]

Security Operating Platform for Smart Manufacturing and Industry 4.0

Information technology is transforming manufacturing by digitizing virtually every step of the modern manufacturing process – a trend referred to as “smart manufacturing” in the United States and “Industry 4.0” in Europe.

Cloud computing, together with technologies such as 5G wireless, smart sensors, high-performance computing (HPC), computer-aided design, engineering and the industrial internet of things, is essential to the smart manufacturing revolution.

Applications in the cloud will impact virtually every aspect of modern manufacturing. At the enterprise level, cloud computing will impact how companies manage their operations, from enterprise resource planning (ERP) and financial management to data analytics and workforce training. The cloud will also prove integral to how manufacturers integrate themselves into industrial supply chains. At the manufactured-product level, cloud computing has begun to transform everything from how products themselves are researched, designed and developed to how they are fabricated and manufactured, and finally, how they are used by customers in the field.

However, as with any change in working practices, there are also some associated risks that must not be ignored.

With smart manufacturing, terminals will be embedded with IoT, which ultimately means that they will be vulnerable to cyberattacks. While this added connectivity helps improve productivity, it is also a weak point in the network which cybercriminals can take advantage of.

Cybercriminals understand the sensitivity of these networks and are also fully aware of the destructive consequences a successful attack can have – lost revenues/profit, brand damage, or a devastating threat to people and assets.

It is therefore imperative that the manufacturing industry take steps to improve security and ensure it is not exposing its systems to cybercriminals.

One of the key challenges with cybersecurity within manufacturing is that attacks are extremely difficult to identify in operational technology (OT) environments. Consider a plant where, for an unknown reason, a certain SCADA component suddenly stops working. Chances are that “malicious activity is going on,” would not be the first consideration when trying to work out what has gone wrong. In 9 out of 10 cases, the root cause is likely to be benign. But what about that one time when there is a more suspicious root cause?

Monitoring services exist for OT environments, but they have limited visibility and offer only correlated, contextual information due to the necessity for network zones, or segmentation. This means that sensors need to be placed at several different layers within the network to monitor end-to-end activity. Another contributing factor is complexity, even if network traffic is being captured. When systems go down, many organizations are completely focused on getting them up and running again rather than mining big data sets to determine categorically what went wrong.

As organizations adopt smart manufacturing/Industry 4.0 working practices, cybersecurity is increasingly paramount. With this in mind, learn how to protect yourself against sophisticated cyberattacks with Palo Alto Networks Security Operating Platform.

[Palo Alto Networks Research Center]

English
Exit mobile version