Analytics
9/12/2013
11:33 AM
Dark Reading
Dark Reading
Products and Releases
Connect Directly
RSS
E-Mail
50%
50%

New Industrial Control Systems Cyber Security Certification In Development

Objective of collaborative is to develop a vendor-neutral certification to be known as the Global Industrial Cyber Security Professional (GICSP)

BETHESDA, Md., Sept. 12, 2013 /PRNewswire-USNewswire/ -- Global Information Assurance Certification (GIAC), a leading provider of cyber security certifications, and representatives from a global industry collaborative announce today that they have formed a community initiative to establish an open body of knowledge for Process Control Design and Information Technology Security. The objective of the collaborative, involving organizations which design, deploy, operate, and maintain industrial automation and control system infrastructure, is to develop a vendor-neutral certification to be known as the Global Industrial Cyber Security Professional (GICSP) to debut this fall. The GICSP will be available to candidates in late November 2013. For more information, please visit: http://www.giac.org/info/139030

"Protecting industrial control and automation systems from constantly evolving cyber security threats is a very challenging task shared by all involved stakeholders. The foundation for any successful program is the people involved in developing, designing, operating and maintaining these systems. We are therefore proud to be part of the creation of the first professional certification program for industrial control system cyber security. The effort did not only result in a certification program that will advance workforce development, but it is also an industry commitment to improve the security of our critical infrastructure," stated Markus Braendle, Group Head of Cyber Security, ABB, Zurich, Switzerland.

Warnings about attacks to critical infrastructure have been circulating for years, but in recent years real threats have been identified and have had an identifiable impact on critical infrastructure assets and systems. Critical infrastructures, such as power utilities and the oil and gas industry, must keep the operational environment safe, secure and resilient against current and emerging cyber threats to maintain the safety of workers and well being of customers and the communities they serve. One of the key challenges these industries are facing is educating and certifying a workforce that need to possess the knowledge, skills and abilities to securely deploy and maintain process control systems. The GICSP is being developed to meet this challenge.

"Managing cyber risk is an issue effecting the entire energy industry ecosystem and in order to effectively implement and sustain security controls on industrial infrastructure, we're all reliant on a complex ecosystem of people (system vendors, project engineering contractors, process operators, IT service providers and maintenance/support personnel) who require a blended set of IT/Engineering/Cyber Security competencies - a skill-pool which is unique and scarce in today's marketplace," said Tyler Williams, Manager, PCD IT Security Solutions at Shell and Chair of the industry consortium. "Developing and maintaining this workforce can be a challenge for any one organization and that is why we support this collaborative effort to establish a community developed body of knowledge and certification program for industrial cyber security. "

GIAC and the industry leaders have worked to establish a panel of Subject Matter Experts (SME) to identify the knowledge, skills and abilities necessary to develop the certification objectives for the GICSP. The SME panel met in Houston, Texas in May 2013, to begin this process. A further outcome of the SME panel is to develop a Job Task Analysis survey, which is sent to a broad array of critical infrastructure participants to ensure the certification aligns to job duties. The GICSP expects adoption on a global basis as a gateway certification in the cyber security domain for industrial control systems.

"GIAC is actively engaging with industrial control systems (ICS) security and engineering experts to develop a broad based and foundational certification that will begin to prepare enterprises, global agencies and governments to mitigate and implement a process to address ICS cyber security concerns," said Michael Assante, SANS ICS Director.

The global industry experts involved in this initiative include representatives from the following national and international companies:

-- ABB

-- BP

-- Cigital

-- Cimation

-- Emerson Process Management

-- Global Information Assurance Certification

-- Industrial Automated and Control Systems & Smart Grids Thematic Group,

ERNCIP project, European Commission's Joint Research Centre

-- Invensys

-- KPMG

-- Pacific Gas & Electric

-- Phoenix

-- Red Tiger Security

-- Rockwell Automation

-- SANS Institute

-- Schneider Electric

-- Shell

-- TNO

-- Wurldtech

-- Yokogawa

About GIAC

Global Information Assurance Certification (GIAC) is a certification body featuring over 25 hands-on, technical certifications in information security.

GIAC has certified over 51,000 IT security professionals since it was founded in 1999. The GIAC program is accredited under the IEC/ISO/ANSI 17024 quality standard for certifying bodies. GIAC is an affiliate of the SANS Institute.

(www.GIAC.org)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Threat Intel Today
Threat Intel Today
The 397 respondents to our new survey buy into using intel to stay ahead of attackers: 85% say threat intelligence plays some role in their IT security strategies, and many of them subscribe to two or more third-party feeds; 10% leverage five or more.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6306
Published: 2014-08-22
Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges via unknown vectors.

CVE-2014-0232
Published: 2014-08-22
Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1)...

CVE-2014-3525
Published: 2014-08-22
Unspecified vulnerability in Apache Traffic Server 4.2.1.1 and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.

CVE-2014-3563
Published: 2014-08-22
Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3) salt-cloud.

CVE-2014-3594
Published: 2014-08-22
Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new host aggregate name.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.