Analytics
9/12/2013
11:33 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

New Industrial Control Systems Cyber Security Certification In Development

Objective of collaborative is to develop a vendor-neutral certification to be known as the Global Industrial Cyber Security Professional (GICSP)

BETHESDA, Md., Sept. 12, 2013 /PRNewswire-USNewswire/ -- Global Information Assurance Certification (GIAC), a leading provider of cyber security certifications, and representatives from a global industry collaborative announce today that they have formed a community initiative to establish an open body of knowledge for Process Control Design and Information Technology Security. The objective of the collaborative, involving organizations which design, deploy, operate, and maintain industrial automation and control system infrastructure, is to develop a vendor-neutral certification to be known as the Global Industrial Cyber Security Professional (GICSP) to debut this fall. The GICSP will be available to candidates in late November 2013. For more information, please visit: http://www.giac.org/info/139030

"Protecting industrial control and automation systems from constantly evolving cyber security threats is a very challenging task shared by all involved stakeholders. The foundation for any successful program is the people involved in developing, designing, operating and maintaining these systems. We are therefore proud to be part of the creation of the first professional certification program for industrial control system cyber security. The effort did not only result in a certification program that will advance workforce development, but it is also an industry commitment to improve the security of our critical infrastructure," stated Markus Braendle, Group Head of Cyber Security, ABB, Zurich, Switzerland.

Warnings about attacks to critical infrastructure have been circulating for years, but in recent years real threats have been identified and have had an identifiable impact on critical infrastructure assets and systems. Critical infrastructures, such as power utilities and the oil and gas industry, must keep the operational environment safe, secure and resilient against current and emerging cyber threats to maintain the safety of workers and well being of customers and the communities they serve. One of the key challenges these industries are facing is educating and certifying a workforce that need to possess the knowledge, skills and abilities to securely deploy and maintain process control systems. The GICSP is being developed to meet this challenge.

"Managing cyber risk is an issue effecting the entire energy industry ecosystem and in order to effectively implement and sustain security controls on industrial infrastructure, we're all reliant on a complex ecosystem of people (system vendors, project engineering contractors, process operators, IT service providers and maintenance/support personnel) who require a blended set of IT/Engineering/Cyber Security competencies - a skill-pool which is unique and scarce in today's marketplace," said Tyler Williams, Manager, PCD IT Security Solutions at Shell and Chair of the industry consortium. "Developing and maintaining this workforce can be a challenge for any one organization and that is why we support this collaborative effort to establish a community developed body of knowledge and certification program for industrial cyber security. "

GIAC and the industry leaders have worked to establish a panel of Subject Matter Experts (SME) to identify the knowledge, skills and abilities necessary to develop the certification objectives for the GICSP. The SME panel met in Houston, Texas in May 2013, to begin this process. A further outcome of the SME panel is to develop a Job Task Analysis survey, which is sent to a broad array of critical infrastructure participants to ensure the certification aligns to job duties. The GICSP expects adoption on a global basis as a gateway certification in the cyber security domain for industrial control systems.

"GIAC is actively engaging with industrial control systems (ICS) security and engineering experts to develop a broad based and foundational certification that will begin to prepare enterprises, global agencies and governments to mitigate and implement a process to address ICS cyber security concerns," said Michael Assante, SANS ICS Director.

The global industry experts involved in this initiative include representatives from the following national and international companies:

-- ABB

-- BP

-- Cigital

-- Cimation

-- Emerson Process Management

-- Global Information Assurance Certification

-- Industrial Automated and Control Systems & Smart Grids Thematic Group,

ERNCIP project, European Commission's Joint Research Centre

-- Invensys

-- KPMG

-- Pacific Gas & Electric

-- Phoenix

-- Red Tiger Security

-- Rockwell Automation

-- SANS Institute

-- Schneider Electric

-- Shell

-- TNO

-- Wurldtech

-- Yokogawa

About GIAC

Global Information Assurance Certification (GIAC) is a certification body featuring over 25 hands-on, technical certifications in information security.

GIAC has certified over 51,000 IT security professionals since it was founded in 1999. The GIAC program is accredited under the IEC/ISO/ANSI 17024 quality standard for certifying bodies. GIAC is an affiliate of the SANS Institute.

(www.GIAC.org)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Threat Intel Today
Threat Intel Today
The 397 respondents to our new survey buy into using intel to stay ahead of attackers: 85% say threat intelligence plays some role in their IT security strategies, and many of them subscribe to two or more third-party feeds; 10% leverage five or more.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5395
Published: 2014-11-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users ...

CVE-2014-7137
Published: 2014-11-21
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM before 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet/tasks/contact.php; (4...

CVE-2014-7871
Published: 2014-11-21
SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call.

CVE-2014-8090
Published: 2014-11-21
The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nes...

CVE-2014-8469
Published: 2014-11-21
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?