Industrial Control Systems (ICS) Security Resources and Tools

The Roadmap Implementation Working Group, composed of the U.S. Department of Homeland Security (DHS) and industry volunteers, has collected a wealth of reference information designed to assist owners and operators in addressing industrial control systems (ICS) security. Key resources include:

Cyber Security Evaluation Tool (CSET) DHS offers the CSET for companies interested in an assessment methodology. This tool can be downloaded at http://www.us-cert.gov/control_systems/satool.html.

Cybersecurity Tabletop Exercise – This exercise is scalable and adaptable for your company allowing you to explore and address cybersecurity challenges. It includes an option of two scenarios – control systems and business systems. All materials and templates are provided for a minimal planning effort. Downloaded the exercise here.

The Industrial Control Systems – Cyber Emergency Response Team (ICS-CERT)The Industrial Control Systems – Cyber Emergency Response Team (ICS-CERT) is a key resource for situational awareness for the process control and automation industries. The Roadmap Awareness materials contain several resources from ICS-CERT, including an overview of national ICS incident reporting as well as the most prominent cyber threat trends and vulnerabilities pertinent to ICS.   

Industry Standards, Relevant Guidance, and Additional References The Roadmap Implementation Working Group developed Industry Standards, Relevant Guidance and Additional References. This guide is designed to facilitate research on existing standards in the area of control systems security. The guide highlights two resources for industry standards, as well as five resources for relevant guidance, and several additional reference resources on ICS security topics. 

Procurement LanguageThe Department of Homeland Security: Cyber Security Procurement Language for Control Systems provides sample recommended language for control systems security requirements. The document provides example language to incorporate into procurement specifications. ICS asset owners and users can change or modify document language as needed to meet individual procurement needs. 

Training Resource The Roadmap Implementation Working Group developed the Chemical Sector ICS Security Training Resource. This guide of available training is designed for professionals who work in areas relevant to the process control and automation industries. The information is organized by levels of difficulty – introduction; intermediate; advanced. For ease of access, the guide includes links to relevant Web sites.

All of this information and more is available through the Roadmap Awareness Campaign DVD. To obtain a copy, please email chemicalsector@dhs.gov.