Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

ICS-CERT Examines 3 Years of Data to Reveal Common Vulnerabilities for Critical Asset Owners

Lack of formal documentation, event monitoring, and permissions and privileges control, remain common among industrial control system environments, according to the Department of Homeland Security.

Lack of formal documentation, event monitoring, and permissions and privileges control, remain common among industrial control system environments, according to the Department of Homeland Security.

The assessment identified security gaps in the enterprise and control system networks for over 230 critical asset owners, the Industrial Control Systems-Computer Emergency Response Team (ICS-CERT) said in its latest issues of ICS-CERT Monitor. The assessments were designed to strengthen the country’s critical infrastructure’s overall security posture.

Lack of formal documentation for processes and policies within the organization was a common security gap across industrial control system operators, owners, and manufacturers, ICS-CERT said. Poor systems access controls in place meant organizations were not properly controlling who had the proper permissions to access the network and various resources. Privilege management and access controls are important in these kind of sensitive networks.

“ICS-CERT encourages asset owners to review their network for these common security gaps and take measures to eliminate known system vulnerabilities,” ICS-CERT wrote.

Another common gap was in event monitoring, as organizations were falling behind on audits and accountability. This included issues such as not having security audits or assessments at all, and poor—or none at all— logging practices. For some organizations, the network architecture was not well understood, or the administrators were not consistently enforcing remote login policies or controlling incoming and outgoing media.

ICS-CERT used the newly launched CyberSecurity Evaluation Tool (CSET) and compared each organization’s security practices against accepted industry standards.

Advertisement. Scroll to continue reading.

Other common security weaknesses included improper authentication controls and credentials management. In many cases, the network was designed poorly, such as not defining a security perimeter or improperly configured firewalls. Network devices were not properly configured and some in some cases, there was little or no monitoring by intrusion detection systems taking place. Along with improperly deployed network devices, the assessment uncovered configuration issues, such as weak testing environments, weak backup and restore capabilities, and poor or limited patch management.

The three year onsite assessment reviewed existing customer systems to discover possible vulnerabilities as well as developing strategies for effective defense-in-depth processes. Organizations also learned about national cybersecurity standards, industry-based recommendations, and best practices as part of the assessment.

“The assessments also assisted these organizations in identifying and prioritizing their most critical vulnerabilities requiring immediate attention and provided real-time resolutions and recommendations for enhancing their security awareness and defensive posture,” ICS-CERT said.

Related ReadingCritical Infrastructure is the New Battleground for Cyber Security

Related ReadingPutting SCADA Protection on the Radar

Related Reading: SCADA Honeypots Shed Light on Attacks Against Critical Infrastructure

Written By

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.