CYBERSECURITY REVIEW 19 JUNE - JULY 2022FEDERAL CYBERSECURITY REGULATION IMPACTS ON AEC COMMUNITYBy David Brearley, Operational Technology Cybersecurity Director, HDRCXO INSIGHTSMost people associate cybersecurity with protecting important data on information technology (IT) systems or the internet, however, Operational Technology (OT) systems are vulnerable too. OT describes a class of systems which are programmable systems that control a system with physical response. The US Department of Defense (DoD) also calls these systems Facility Related Control Systems (FRCS). Examples within the vertical build environment include HVAC, Fire Life Safety, Electrical, Metering, Elevators, and Water/Wastewater Systems. The effects of a cyber- attackon an OT system can impact life and equipment safety, environmental or regulatory impact, financial impacts, or may leveraged as an entry point to a higher value target on a common network. The AEC industry serving the DoD has been adapting to Unified Facilities Criterion (UFC) 4-010-06 Cybersecurity of Facility Related Control Systems requirements since 2017 with many of the early UFC compliant projects recently completing construction. In July 2021 the White House issued "National Security Memorandum on Improving Cybersecurity for Critical Infrastructure Control Systems". This call to action has resulted in a renewed focus on securing OT systems and will further develop standards, regulations and requirements. Cybersecurity risks cannot be eliminated and therefore must be mitigated to an acceptable risk tolerance.The DoD has implemented the NIST 800-137 Risk Management Framework (or RMF) to analyze the risk and apply acceptable cybersecurity mitigations to achieve acceptable risk tolerance to OT systems and published this process as the Unified Facilities Criteria 4-010-06. Other agencies including Veteran Affairs (VA) and private industry are utilizing RMF methodologies during design to develop construction requirements. We will review the 6-step RMF process including roles and responsibilities:STEP 1 CATEGORIZE SYSTEM(S)· Designer and System Owners will coordinate early in design (15% per UFC) to determine the potential impact of a cybersecurity incident to each OT system in terms of Confidentiality, Integrity and Availability. David Brearley
<
Page 9 |
Page 11 >