Purchasing Language for SCADA systems…

Feb. 27, 2008
Todd Stauffer of Siemens and I were discussing the need for critical engineering understanding when applying cybersecurity tools to plant level DCS and SCADA security the other day. Todd reminded me of the fact that there's a government funded organization called the Multi-State Information Sharing and Analysis Center that has produced a soi-disant set of procurement language for SCADA systems that is intended to help end...
Todd Stauffer of Siemens and I were discussing the need for critical engineering understanding when applying cybersecurity tools to plant level DCS and SCADA security the other day. Todd reminded me of the fact that there's a government funded organization called the Multi-State Information Sharing and Analysis Center that has produced a soi-disant set of procurement language for SCADA systems that is intended to help end users and EPCs ensure an appropriate level of cybersecurity when they buy and specify SCADA systems. I assume this also applies to DCS systems and simpler plant control systems. MSISAC is a venture of the State of New York and Idaho National Laboratory (INL). Yes, those people who brought you the Aurora video. MSISAC has posted several iterations of their recommended language document which they hope somebody will take and incorporate into real specifications for how to design and purchase cybersecure SCADA systems. What Todd and I were talking about was the need to actually know something about plant and utility control systems before attempting to use this document, in any of its iterations. Todd pointed out that it is entirely possible to specify ALL of the options in the documents, thus making it impossible to actually procure a system at all. What has to happen, when you use documents like this, is you have to have the engineering expertise and sound engineering judgement to be able to use the documents as a template, a framework, and not a stencil. We also noted in passing Boeing's problems with interconnected networks and the new 787 Dreamliner. I have previously noted, in Sound Off! about the folks from Boeing who spoke at ARC...who said that engineers wanted to be able to flash the solid state memories of the avionics systems anytime they wanted to--- and I hope I'm never on a 787 if they are allowed to log onto the avionics and flash the ROMs when the plane is at 40,000 feet. Walt Boyes

Sponsored Recommendations

Make Effortless HMI and PLC Modifications from Anywhere

The tiny EZminiWiFi is a godsend for the plant maintenance engineers who need to make a minor modification to the HMI program or, for that matter, the PLC program. It's very easy...

The Benefits of Using American-Made Automation Products

Discover the benefits of American-made automation products, including stable pricing, faster delivery, and innovative features tailored to real-world applications. With superior...

50 Years of Automation Innovation and What to Expect Next

Over the past 50 years, the automation technology landscape has changed dramatically, but many of the underlying industry needs remain unchanged. To learn more about what’s changed...

Manufacturing Marvels Highlights Why EZAutomation Is a Force to Be Reckoned With

Watch EZAutomation's recent feature on the popular FOX Network series "Manufacturing Marvels" and discover what makes them a force to be reckoned with in industrial automation...