to Episode 10 Off cybersecurity Architectural Fundamentals.
Today we should recovering the topics on
Internet off Thanks security
and manage Security Service's consideration When architect ing a system.
with I o T Security.
Are you t security covers the protection off sensors and the collected data.
There is a need to consider the physical security off the devices
and the validity off the data collected
In this case, we're not just talking about the data being stolen,
but more that data being corrupted by a cyber attack.
What other threats toe I ot security?
Well, listen, formals,
it is still very consumer centric.
Many off the OT devices today are still focused on the consumer market. Like your I P cameras, all your well, a senses and so on.
There seems to be a lack off security considerations in many of these products,
although that is changing. But this is still one of the biggest problem
s with Mobil's. There are way too many variants off i ot platform.
Although many of them have built their platform on open source platforms like clinics or android,
they're still very preparatory components in many off these devices.
the support for protocols is not uniform. There are still many ways in these devices. Communicate back to your service. This is the evolving space. Many off these concerns will not go away soon.
As the security architect, you need to design the security of systems to cater. For these to be swapped out when the time is right,
here is another view off I ot security threats
using the model off threats and versus assets. This view lets you identify assets in your eye, OT eco system and the treads pertaining to it.
There is no right and wrong way to model it, but choose one that works
for your environment and one that you can use to communicate to your stakeholders.
Do visit the link shown below to understand more about this model and see if it's applicable to your environment.
Here are some off the common tools and techniques that can help you secure your eye ot environment.
One off the emerging techniques is the use off micro certificates, too and crypt
and secure your traffic between devices.
Traditional P k I might be too heavy
for the small computer capabilities off the devices.
Therefore, there was an emerging market off, creating micro certificates to replicate what p. K I does for systems on a micro level
checking the implementation of Io ti. It's also very important. This includes getting people with the right knowledge to do I ot penetration testing.
It's a different skill set from the typical weapon application. Therefore, you need people well versed in the various treads and how to do a proper penetration test.
You can also consider using highly scalable VPN to secure the traffic. For example, Siskel's group and group that traffic VPN, which helps aggregate and combined data through one big V P and pipe.
This is just one way to secure
such amount of traffic that are located near each other.
And if you're using industries that protocol like M. Q T T, make sure you secure the transport for example, using T. L s on your amputee T
as this is an emerging feel,
pay attention to publications in journals and find out more about what can be done
to secure your T devices.
Moving on to manage security service is
many architects do not pay enough attention to how their design with affect a managed service or the constraints of manage security Service's
on the architecture off a system.
Today. Most manage security service providers are usually very focused
and less so on the application
and most off the service delivery.
Our constraints by your contracts and service level agreements that you have signed, too,
pay particular attention to what is the S. L. A's promise, and does it fit into your security posture
as it is a managed service,
you have to be very clear on the scope off coverage.
Do not assume an incident it's covered or type of tread is covered. Do make sure you go through all the use cases were negotiating. A managed security service's
also understand what it's the contractual obligation off these providers to you.
How much information do they need to give you and how much openness will they give you an excess to some of the locks collected.
Service level agreements need to be reviewed regularly to see if it is relevant to the current threat landscape
and ensure that the service provider is delivering on them.
S most managed service is is provided off site.
Do take care off. What is the on site remediation plan and how much of it is the responsibility versus your responsibility.
This diagrams helped you to clarify areas which you need to discuss with your service provider.
On the top will be some service management like S L. A. And service provisioning
and their lifecycle. Also pay attention to things like the change management, incident management, forensics investigation and event monitoring.
Also, do not forget the items on the right that covers governance, but it's a policy to strategy the risk management. And if you are regulated industries, what are your legal and regulatory compliance
Also ensure the boundaries off the scope?
Where is the handoff and where do they stop monitoring or pick up monitoring?
It pays to go true. Various use cases to ensure that your entire and toe end security coverage it's managed both by you and your service provider.
Some off the additional tools and techniques. You can do this, for example,
have a technical measure off in tunnel second line defense. What that means is, maybe in some critical areas you have your own monitoring and lyrically do an audit on the events you pick up versus the events picked up by your service provider
and, as mentioned earlier as it is
a contract that service, please ensure that your contractual protections are in place,
that you have sl a management and you have to write toe ordered their processes and the work they deliver.
Another way to medicate risks here,
this partnership all core saucing.
That means maybe the service providers sits on your premise. I r
intermix with your team so that there is an easy way to exit, if necessary
today. Recovered. I ot security
What we need to look up for.
Pay attention to not only data exploitation but data manipulation.
Many cases data collected from Io ti is used in the Data Lake to help feed
you're a I or ml engines.
An attack could be feeding back data. True, you're I oti senses to skew your artificial intelligence.
Also do ensure that if your architect ing a solution and using a manage security service provider
that your system will allow them to pick up events and that their alerts will come back to you in a timely fashion,
here are two good resource is to read up on this topic
one the next publication off consideration for managing I ot cyber security and privacy risks.
And the second is from an information each article six things to look for in a managed service provider.
Thes would give you a little bit more details on the topics cover earlier.
This episode concludes
theat Vons and the price security areas.
Next, we will look into cybersecurity processes and how they would affect the architecture off a system.
If you have time, please join me for a next session.