The NIST Cybersecurity Framework – A Step Forward or a Waste of Money 0
The NIST Cybersecurity Framework – A Step Forward or a Waste of Money

You may have heard some buzz in the press (both US and International) about the release of the Cybersecurity Framework Draft from the US National Institute of Standards and Technology (NIST). However, you may not know much about its background. And you probably don't know what it may mean to you as a control or security professional. This blog post will give you a high level overview of the genesis of this document and some handy points of reference. 

read more »
New SCADA Security Flaws Part 2: DPI Firewalls an Important Part of the Solution 0
New SCADA Security Flaws Part 2: DPI Firewalls an Important Part of the Solution

In last week's Practical SCADA Security blog, I discussed how the new vulnerabilities discovered in DNP3 SCADA masters are carving big holes in the NERC's concept of the Electronic Security Perimeter (ESP). Dale Peterson started the ball rolling in his blog "Why the Crain/Sistrunk Vulnerabilities are a Big Deal". Then Darren Highfill posted a blog explaining that the vulnerabilities don't even require the attacker climb a fence.

read more »
New SCADA Flaws Part 1: Forget NERC’s Electronic Security Perimeter 0
New SCADA Flaws Part 1: Forget NERC’s Electronic Security Perimeter

If you have been following SCADA news in the last month, you might have noticed an avalanche of reports and blogs on new security vulnerabilities in power industry equipment. So far, vulnerability disclosures for 9 products using the DNP3 protocol have been released by the ICS-CERT, with another 21 SCADA product disclosures reportedly on their way. Even the New York Times and Wired Magazine have picked up this story.

 

read more »
up
Shop is in view mode
View full version of the site
Sklep internetowy Shoper.pl