The US cybersecurity agency CISA and Australia’s Cyber Security Centre (ACSC) have published joint guidance detailing how critical infrastructure (CI) organizations can isolate vital OT and supporting systems.
Aimed at boosting cyber resilience, the CI Fortify – Advice for isolating vital systems guidance also includes details on how these systems can be operated in isolation for long periods, to ensure the continuity of critical services in case of disruption or crisis.
The document is designed to help OT owners, operators, and cybersecurity teams improve their preparedness, response, and recovery.
“In response to persistent threats, CI operators should have the capability to isolate vital OT and enabling systems from all other networks to ensure continuity of critical services. Isolating vital OT and enabling systems can disrupt the ability of malicious cyber actors to achieve their goal, contain active incidents, and allow for safe rebuilding of compromised systems,” the guidance reads.
CI organizations should start by identifying all systems and networks supporting critical services, as well as customers that depend on critical infrastructure.
Next, they should identify the common levels of criticality and trust for systems and networks, and determine how they should be grouped in segments and zones to manage risk and apply controls better.
After identifying and classifying vital systems and networks, organizations should identify and record the connections between them and other systems, such as non-critical corporate systems, vendor remote access, untrusted networks, cloud environments, and peer critical networks.
For each connection, critical technical information should be documented and periodically updated.
“It is important to note that isolating systems will trigger manual processes and interrupt system-to-system communication. This can impact connections to upstream dependencies and peers, such as other utilities and scheduler or dispatch operators. Organizations should identify and work through critical dependencies with impacted peers and partners as part of their isolation planning,” the guidance reads.
CI operators should also build effective separation and isolation points between critical and non-critical services and networks, to limit threat actors’ ability to reach vital systems. These isolation points also help with containment and remediation and limit the impact an intrusion has on operations.
“Planned physical separation of vital systems from all other networks and systems is a pre-requisite for physical isolation. Organizations must build physical isolation points into their vital systems to enable the capability to operate in a state of isolation from all other networks and systems,” the guidance reads.
Finally, organizations should create, test, and review a graduated plan for isolation that enables them to progressively isolate pathways to vital systems while maintaining business continuity.
CI operators are also advised to monitor the effectiveness of the isolation mechanisms throughout the isolation period, to ensure that no connection between critical and non-critical networks occurs.
CISA and ACSC also detail the operational and security risks that adopting CI Fortify introduces, such as a lack of patching, reduced external visibility, and an increased risk of infection via removable media, and advise organizations to account for them when operating in isolation.
Additional resources for CI operators can be found on CISA’s CI Fortify: Strengthening Resilience Across Critical Infrastructure page.
Related: NIST Opens Updated IoT Security Guidance to Public Review
Related: CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk
Related: G7 Countries Release AI SBOM Guidance
Related: Global Cyber Agencies Issue AI Security Guidance for Critical Infrastructure OT