Cyber Security for Industrial Automation and Control Systems (IACS)
- Publisher
- HSE · UK Health and Safety Executive
- Type
- Guidance
- Date
- Unknown
- Themes
- Process SafetySecurity
Summary
HSE inspection guide for cyber security of industrial automation and control systems on offshore installations, defining three categories of inspection.
Summary written automatically from the title and document text.
Themes: process safety, security.
Extract from the document (first pages)
Text extracted automatically from the publisher’s PDF so it can be searched. Layout, tables and figures are lost and the extract stops after the first pages; read the document itself at HSE.
Cyber Security for Industrial Automation and Control Systems (IACS) Inspection Guide Open Government Status
Fully Open
Publication Date
19 March 2021
Review Date
19 March 2024
Review History
Version Date Changes Approved 1 First Draft for Comment 01/12/2018 First issue John Pirie
2 Revised following Stakeholder 01/11/2019 Introduction of BCS John Pirie Engagement collaboration Inspection pack for Non-NIS installations 3 Issued for IPAG approval 09/01/2020 Comments from v2 John Pirie added
4 Issued to external stakeholders 22/04/2020 Comments from IPAG John Pirie for comment added
5 Issued to IPAG for final approval 25/01/2021 Comments from John Pirie external stakeholders added. 6 Final Issue approved for use 12/03/2021 None John Pirie
Target audience
Energy Division offshore inspection management teams (IMT), specialist inspectors and IACS responsible persons
Contents Summary ................................................................................................................... 2 Introduction .............................................................................................................. 3
NIS Regulated Installations ..................................................................................... 4 Non-NIS Regulated Installations ............................................................................. 4 Cyber Security Category Inspection Selection Matrix .......................................... 5 Action ........................................................................................................................ 7 Safety Case and Thorough Reviews....................................................................... 7 Performance Standards ........................................................................................... 7 Background .............................................................................................................. 7 Organisation ............................................................................................................. 8 Targeting ................................................................................................................ 8 Timing ..................................................................................................................... 8 Resources .............................................................................................................. 8 Recording and Reporting ........................................................................................ 8 Health and Safety ................................................................................................... 9 Diversity .................................................................................................................. 9 Relevant Legislation ................................................................................................ 9 Contacts .................................................................................................................... 9 Glossary of Terms .................................................................................................... 9 Appendix 1 Category 1 Cyber Security Inspection ............................................. 11 Appendix 2 Category 2 Cyber Security Inspection ............................................. 13 Appendix 3 Category 3 Cyber Security Inspection ............................................. 15 Appendix 4 - Basic Cyber Security Inspection Pack (BCSIP) ............................ 17
Summary The purpose of this inspection guide (IG) is to provide information and guidance to Offshore Safety Directive Regulator (OSDR) inspectors to support the delivery of consistent and effective inspection of both duty holder’s (DH) and operators of essential services (OES) arrangements of cyber security for industrial automation and control systems (IACS) used on the United Kingdom Continental Shelf (UKCS).
It implements the process described in HSE’s OG86 guidance Cyber Security for Industrial Automation and Control Systems (IACS) EDITION 2, and applies to both NIS and Non-NIS regulated installations.
It delivers a proportional and targeted approach to cyber security inspections for initial and subsequent cyber security inspections on both network information systems (NIS) and non-NIS installations via the following three categories
Category 1 Initial onshore cyber security inspection of cyber assessment framework (CAF) self- assessment responses and improvement plans for all NIS regulated installations
Category 2 Initial onshore cyber security inspection of basic cyber security inspection pack (BCSIP) self-assessment responses and improvement plans for targeted non-NIS regulated installations.
Category 3 Onshore/offshore cyber security inspection as part of a planned intervention multi- topic inspection of all subsequent NIS and non-NIS installations and those not targeted for a category 2 cyber inspection in accordance with the Cyber Security Category Inspection Selection Matrix shown in figure 2.
Figure 1 shows the relationship between the three categories of inspection
Introduction HSE have published Operational Guidance document OG86 Cyber Security for Industrial Automation and Control Systems (IACS) for use on major hazardous workplaces for onshore (COMAH regulated sites), offshore (SCR2015 regulated installations) and loss of essential services NIS regulated sites (OES sites) (onshore and offshore).
The primary objective of OG86 being to enable HSE inspectors to verify or otherwise the adequacy of an OES/DH IACS cyber security management system, including competence management and the effectiveness of cyber security countermeasures on major accident workplaces and operators of essential services covered under the NIS Regulations.
IACS typically includes basic process control systems (having the ability to view and manipulate the equipment under control or containing any independent protection layer functions (IPLs) that are providing risk reductions), safety systems, electrical control / data acquisition systems and the associated information and business systems connected via the IACS network infrastructure.
For offshore this may also include systems such as marine, drilling and helicopter motion monitoring systems.
NIS Regulated Installations The competent authority for the Network and Information Systems Regulations 2018 (NIS) is the secretary of state for Business, Energy and Industrial Strategy (BEIS), who signed an agreement in May 2018 for HSE to carry out the functions described in the regulations on behalf of BEIS.
NOTE: The Offshore Petroleum Regulator for Environment and Decommissioning (OPRED) do not carry out any of the functions described in the NIS Regulations
One of the requirements from BEIS is for OESs to complete a cyber security self- assessment based on the National Cyber Security Centre’s (NCSC) Cyber Assessment Framework (CAF) Indicators of Good Practice (IGP), along with delivering a Cyber security improvement plan arising out of the assessment. This provides systematic and structured “indicators of good practice “(green/amber/red) of the OES’s cyber “hygiene” along with a gap analysis against their “target profile” and action plan which must be submitted to BEIS.
Energy Division (ED) uses the output from the completed self-assessment as a starting point for NIS inspections. The objective being to use the information to carry out a sample-based inspection of the CAF objectives, principles, and outcomes against the requirements of OG86 (or an equivalent standard).
Note 1 OG86 guidance is aligned to the CAF objectives, principles, and outcomes.
Note 2 Version 3 of the CAF replaced the term “Loss of Essential Services” to “Loss of Essential Functions” in order for the CAF tool to be used for health and safety consequences and can be used on non-NIS regulated installations.
The initial inspection of all NIS regulated installations will include an onshore CAF progress inspection followed by an onshore detailed cyber security inspection against the requirements of OG86 (or an equivalent standard). This type of inspection is called a Category 1 cyber security inspection and is described in Appendix 1.
Subsequent inspections of NIS regulated installations will form part of a multi- discipline onshore/offshore intervention which will align with ED’s intervention plans. This type of inspection is called a category 3 cyber security inspection and is described in Appendix 3.
Non-NIS Regulated Installations Non-NIS regulated installations will follow a similar inspection process to NIS installations in that some targeted DHs operating these types of installations will be required to complete an equivalent CAF self-assessment (and improvement plan)
Note 3 The CAF for these installations has been reformatted and only requires a response from those IGPs of outcomes related to the basic level of countermeasures
to address the lower levels of risk in the CAF. The non-NIS reformatted CAF is called a basic cyber security inspection pack (BCSIP) and is included in Appendix 4.
The initial inspection of those targeted non-NIS regulated installations will use the BCSIP response and improvement plan to facilitate a targeted onshore detailed cyber security inspection against the requirements of OG86 (or an equivalent standard). This type of inspection is called a category 2 cyber security inspection and is described in Appendix 2.
Subsequent inspections of non-NIS regulated installations will form part of a multi- discipline onshore/offshore intervention which will align with ED’s intervention plans. This type of inspection is called a category 3 cyber security inspection and is described in Appendix 3.
Cyber Security Category Inspection Selection Matrix Figure 2 below is the qualitative matrix which will be used by ED inspectors to determine the category of inspection.
Maroon coloured boxes - Category 1 Cyber Security Inspection Initial onshore cyber security inspection of CAF self-assessment responses and improvement plan for all NIS regulated installations shown in figure 1 and described in Appendix 1.
Notes
NIS regulated installations have the highest inspection planning priority.
There may be requirement to re-submit a revised CAF to BEIS prior to a NIS subsequent category 3 inspection.
There is a requirement for the OES to provide a high-level cyber security GANTT chart for all remaining installations showing progress against the improvement plan covering all the installations they operate.
Red coloured boxes - Category 2 Cyber Security Inspection Initial onshore cyber security inspection of BCSIP self-assessment responses and improvement plan for targeted non-NIS regulated installations shown in Figure 1 and described in Appendix 2.
Notes
Targeted non-NIS regulated installations have the second highest inspection planning priority.
A short validation review with the DH will be carried out prior to the issuing of a BCSIP to confirm the major accident hazard (MAH) risk and complexity of their IACS
For DHs operating multiple installations, the category 2 initial inspection may be waived if they have satisfactorily completed and responded to a previous category 1 or 2 cyber security inspection. In this case the installation would only be subject to a category 3 inspection which will take cognisance of the generic CSMS outcomes and improvement plans arising from the category 1 or 2 inspections.
There is a requirement for the DH to provide a high-level cyber security GANTT chart for all remaining installations showing progress against the improvement plan covering all the installations they operate.
Amber coloured boxes - Category 3 Cyber Security Inspection Onshore/offshore cyber security inspection as part of a planned intervention multi- topic inspection of all subsequent category 1 NIS, category 2 non-NIS and the initial inspection of installations not subject to a category 2 inspection shown in Figure 1 and described in Appendix 3.
Notes
Under some circumstances there may be a requirement for a DH to complete a BCSIP prior to, or shortly after, a non-NIS subsequent category 3 inspection.
Under some circumstances there may be requirement for a DH to complete a BCSIP if they only have category 3 installations.
There is a requirement for the OES to provide a high-level cyber security GANTT chart for all remaining installations showing progress against the improvement plan covering all the installations they operate.
Action By the conclusion of the inspection it should be possible to have
• an understanding of the cyber health of the OES/DHs cyber security position • an acknowledgement of any improvement plan and some assurance that the plan will be resourced and executed • revealed any findings related to cyber security that require enforcement action
When carrying out inspections covered by this IG inspectors should
• check the issues against the success criteria in the Appendices • Use the cyber security enforcement management model (EMM) to o form an opinion on the initial enforcement expectation o consider how and when the issues raised during an inspection are to be closed out
Safety Case and Thorough Reviews Duty holders must ensure that cyber security is adequately described in the current accepted safety case by reference to risk assessments and necessary measures for complying with the requirements of OG86 or equivalent standards.
Performance Standards OESs and DHs must now also consider any cyber security related safety and environmental critical elements (SECEs) arising out of the risk assessment which must become part of the verification scheme
Such SECEs could typically have their own performance standard or be merged into existing relevant performance standards.
Background Cyber security as a specific ED topic for inspection evolved out of the introduction of the NIS Regulations and HSE’s OG86 in 2018 and as a consequence of the realisation that IACS installed on offshore installations could be vulnerable to exploitation, either intentionally or accidentally, which could lead to a major accident or a loss of essential services (for those NIS regulated installations).
It was recognised in 2018 that the development of a cyber security inspection guide would benefit from an input from external stakeholders so a small focused team of IACS specialists was set up. Acknowledgements go to the Oil & Gas UK C&I Special Interest Group (previously known as OGOCIN), DNV GL Ltd, Lloyds Register and IADC who provided resources for this cyber security HSE/stakeholder group.
Since 2018 this final version has gone through a continuous improvement process via trial and actual inspection findings, discussion and feedback/comments from the stakeholder group and their members.
Whilst it is expected that relevant standards for IACS cyber security will continue to evolve, this document, along with OG86, provides guidance to inspectors with a practical interpretation of the standards. OG86 makes it clear that it may be used as good practice by OESs/DHs. However, OESs/DHs are free to follow other good practice so long as it provides equivalent protection. i.e. international standards, such as ISA/IEC62443, which continue to evolve and provide standards for analysing cyber risk and to specify the design, installation, inspection, maintenance and testing of cyber security countermeasures.
Organisation Targeting Major accident workplaces where cyber security could pose a major risk to the health and / or safety of employees and / or members of the public and / or environment.
Operators of essential services, as defined in the NIS Regulations, in the energy sector where cyber security could pose a risk to loss of essential services.
This guidance will be applicable to DHs who own / operate IACS along with IACS manufacturers, suppliers, system integrators and 3rd party support companies.
HSE will also use intelligence gathered from safety case assessments, thorough reviews, and combined operation notifications in the intervention strategy.
Timing Ongoing
Resources Energy Division EC&I specialist inspectors during interventions at major accident workplaces or operators of essential services.
Recording and Reporting Due to the sensitivity around the documentation required to carry out the inspection, any information collected or created (i.e. enforcement letters or reports) will be transmitted through a secure file sharing system and only retained in restricted access folders for a maximum of one year after the last issue item has been satisfactorily completed.
All material collected or generated during the inspection is classified as “Official Sensitive” and as such must be restricted and managed in accordance with HSE’s approach to dealing with sensitive cyber security information.
When inspecting the outputs from the systems, a decision will have to be reached on whether the risk control measures implemented led to compliance with the relevant legislation. This decision will be made in the same way as for other inspection topics by comparing the standard of control achieved against the relevant benchmarks and applying the principles of EMM.
The inspection will reach conclusions on overall effectiveness of the DH’s or operators of essential services systems. For NIS regulated installations inspection findings will be separated into NIS-related and MAH related matters. Due to the sensitivity of the information revealed during the inspection cyber related performance scores will not be recorded.
Health and Safety
No special requirements.
Diversity
No special requirements.
Relevant Legislation Refer to OG 86
Contacts Energy Division ED3.5 Electrical, Control and Instrumentation team
Glossary of Terms
AV Anti-virus BCSIP Basic Cyber Security Inspection Pack CAF Cyber Assessment Framework CSMS Cyber Security Management System DMZ Demilitarized Zone Duty holder The person(s) or corporate body that has legal duties under relevant health and safety legislation. In the context of this guidance it will typically be the IACS owner or the IACS operator. GANTT A project management tool assisting in the planning and scheduling of Chart projects of all sizes IACS Industrial Automation and Control System including Safety Instrumented Systems and any SECEs at risk from a Cyber threat. IG Inspection Guide IDS Intrusion Detection Systems IoC Indicators of Compromise LES Loss of essential service (an incident resulting in reduction or disruption of service provision by an OES)
MA Major accident (as defined in legislation (excluding NIS) shown in the ‘relevant regulations’ section of this operational guidance) Major Any place regulated under the legislation (excluding NIS) defined in the accident ‘relevant regulations’ section of this operational guidance workplace NCSC National Cyber Security Centre NIS Network Information Systems NIS Installation covered by Network Information Systems Regulations (NIS) installation Non-NIS Installation not covered by Network Information Systems Regulations installation(NIS) IGP Indicator of good practice IT Information Technology (the use of computers to store, retrieve, transmit, and manipulate data or information. IT is typically used within the context of business operations) OES Operator of Essential Service - The person(s) or corporate body that has legal duties under relevant NIS legislation. In the context of this guidance it will typically be the IACS owner or the IACS operator. OSDR Offshore Safety Division Regulator OT Operational technology (the hardware and software dedicated to detecting or causing changes in physical processes through direct monitoring and/or control of physical devices such as valves, pumps, etc.) Responsible Person or group of persons responsible for IACS cyber security Person (typically not under the management controls of an IT department) Threat Any circumstance or event with potential to adversely impact the IACS UKCS United Kingdom Continental Shelf
Vulnerability Flaw or weakness in a system’s design, implementation, or operation and management that could be exploited to violate the system’s integrity or security
Appendix 1 Category 1 Cyber Security Inspection Category 1 - Initial onshore cyber security inspection of CAF self-assessment responses and improvement plan for all NIS regulated installations
Fundamental Requirement
The OES must have completed the CAF self-assessment tool, identified any gaps, and must have produced an improvement plan to close such gaps.
A CAF progress inspection will be carried out onshore where the OES will be required to present the CAF assessment and the output from the tool (gap analysis and improvement plan).
A more detailed onshore inspection will be carried out either after the improvement plan has been completed or during the life of the improvement plan to inspect the progress against the identified improvements to meet the requirements in OG86 (or an equivalent standard). The inspection agenda will include but not be limited to
• recap of CAF self-assessment results • presentation from the OES on their cyber security improvement plan including the stage of budgets required for implementing the work arising out of the gaps identified from the BCSIP self-assessment • inspection of network topology and IACS • sample inspection of CAF responses against OG86 or an equivalent standard which may include, but not be limited to, an inspection of the CSMS, zoning, risk assessments, asset register and countermeasures from a sample zone/conduit • cyber security planning review of the OES’s remaining (NIS and non-NIS) installations to establish when the following milestones are included in the plan
o CSMS o cyber security asset register o zone and conduit simple network drawings o risk assessment and identification of improvements arising out of the risk assessment o
Links open the HSE publication page or the free PDF on hse.gov.uk; no login is needed.
Crown copyright, reused under the Open Government Licence v3.0, which permits copying and adapting the information with attribution; this site indexes the first pages and links to HSE's own copies, hosting no publisher download files.
Publisher link checked · working