Latest news
The Industrial Control Systems Joint Working Group (ICSJWG) published “The Industrial Control Systems Common Vulnerability Disclosure Framework”, which is a significant step towards standardization of vulnerability disclosure policies for ICS vendors and system integrators.ICSJWG was established by the Department of Homeland Security’s National Cyber Security Division's Control Systems Security Program (CSSP) to assist the industrial control systems stakeholders in better information sharing, raising collaborative efforts and reducing risks related to critical infrastructure.
The newly published framework is to be used as a consensus-based foundation for all involved parties in developing standardized vulnerability disclosure policies. As the framework is aimed towards a diverse set of systems, its content isn’t mandatory but should be used as a valuable starting point towards responsible disclosure.
The document identifies a number of distinct software vulnerability types, mechanisms for their identification and mitigation, vulnerability disclosure scenarios, and provides recommendations on modeling components of a successful policy.
The framework divides industrial control systems software vulnerabilities into architectural, code-based and those in third-party software applications or libraries. Architectural vulnerabilities can occur as a result of insufficient threat modeling in the early phases of software development, as well as in situations where legacy support causes unexpected problems in the seemingly secure environment.
The mitigation of code-based implementation vulnerabilities is not as challenging as that of architectural flaws, since programming errors are easier to identify and patch. Their discovery can be a result of both internal and external analysis and therefore the proposed framework focuses on methods and tools for both approaches.
Third–party software vulnerabilities provide a challenge for ICS vendors, since it is unlikely that they have any direct control over an incorporated library or an embedded application. Because of the complexities that can arise from this type of vulnerability, the document provides some valuable ideas on the remediation process.
An important aspect of the framework proposed by ICSJWG is a four-page write-up on different types of vulnerability disclosure activities. Focusing on both internal and external vulnerability discovery methods, the document examines a set of scenarios including both the discovery of security issues in-house, as well as by a customer or an independent researcher. The framework also identifies three different types of disclosure – private, public, or a third party one. The latter focuses on working with vendor neutral entities such as the Industrial Control Systems Cyber Emergency Response Team (ICS-CERT).
Spotlight

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Is Microsoft is reading your Skype communications?
Posted on 15 May 2013. | The question of whether Skype allows U.S. intelligence and law enforcement agencies to access the communications exchanged by its users has still not been adequately answered by Microsoft.

Internet Explorer best at blocking malware
Posted on 14 May 2013. | While Chrome’s malware download protection improved significantly, Internet Explorer 10 continues to outperform the other browsers with a block rate of 99.96%.

Researcher refuses to help Saudi telco to spy on people
Posted on 14 May 2013. | You would think that a Saudi Arabian telecom firm interested in monitoring its users' mobile communications would not be asking a well-known pro-privacy researcher for help, but you would be wrong.

Malicious browser extensions are hijacking Facebook accounts
Posted on 13 May 2013. | Facebook users - especially those in Brazil - are being targeted with malicious browser extensions trying to hijack Facebook profiles, warns Microsoft.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





