Smith Harney & Daly
Providing Effective Leaders – Secure Operations


Vacancy

  • Expanded Service Offering

    Smith, Harney & Daly LLC – is a professional services firm providing customized business solutions from strategy and leadership development through execution of special projects for our client firms. We support the offices of the President, COO, CMO and CIO, utilizing a customized blend of interim executives, operations, technology and marketing project assistance in addition [...]

  • Smith Harney and Daly Newsletter – June 26

    “Before anything else, preparation is the key to success” -Alexander Graham Bell Interview Tip of the Week When preparing for a Behavioral Interview make sure to prepare for questions pertaining to perseverance, honesty, a time you worked with someone with whom you didn’t get along, time management, problem solving and keeping clients happy. Come up [...]

  • Smith Harney & Daly LLC Newsletter for Monday May 14, 2012

    Interview Tip of the Week How to Interview for a Job – Interviewing Before interviewing it is common for your nerves to be jumping and your mind to be racing. In order to prevent too many jitters, make sure to get in a light workout or de-stressor before the interview. By getting in some exercise [...]

SCADA SECURITY

Click here to find out more!

Industry association aims to bolster SCADA security

The International Society of Automation (ISA) calls for industrial system standard security analysis in wake of Stuxnet.

By George V. Hulme

‘);
// ]]>Click here to find out more! March 11, 2011 — CSO —

It's no state secret that industrial and automation control systems have a way to go before they're resilient from targeted and sophisticated malware attacks. Just last week the International Society of Automation (ISA) announced that the ISA99 standards committee on Industrial Automation and Control Systems Security had formed a task group to conduct a gap analysis of the current ANSI (American National Standards Institute) ISA99 standards and modern threats against critical industrial systems, such as Stuxnet

The ISA 99 standard provides guidance to control system operators on security technologies and how well they work (or don't) at mitigating the risks associated with certain threats and vulnerabilities. The intent of this gap analysis is to determine if organizations that are following ISA 99 would have been able to fend off a Stuxnet-like attack and to identity any improvements the standard may need. A technical report is expected by mid-year 2011.

The ISA 99 standard is a foundation of Supervisory Control and Data Acquisition System (SCADA) security. "Over the next few years, these standards will become core international standards for protecting critical industrial infrastructures that directly impact human safety, health, and the environment; and, likely will be extended to other areas of application, even broader than those generically labeled SCADA. Based on this, it is essential that industrial companies following IEC 62443 standards know they will be able to stop the next Stuxnet," the ISA wrote in its statement announcing the security task force.

The news of the ISA 99 gap analysis came the same day as the Security Incidents Organization released its 2011 report, Report on Cyber Security Incidents and Trends Affecting Industrial Control Systems Resulting from Malware Infections.

"This report shows the details of the continuing threats to manufacturing and infrastructure security around the world. As the Stuxnet malware showed in 2010, the threat continues and has become even more complicated and mature," John Cusimano, executive director of the Security Incidents Organization (SIO), said in a statement.

The threats may be growing more mature and complex, however experts say the vulnerabilities have been laying in wait for some time. "Stuxnet really didn't change anything," says Richard Stiennon, chief research analyst, IT-Harvest and author of the book "Surviving Cyberwar."

"The vulnerabilities have all been there for awhile. Most SCADA networks are pretty wide open and are susceptible to attacks. Stuxnet did, however, open our eyes to what is possible now," he says.

Many industry and critical manufacturing systems are open to not only Stuxnet-like attacks, but also trivial attacks. "Many of these systems are listening on open ports for broadcast messages. And, for example, if they get the right one, they'll reset back to factory settings. There's no authentication of signing processes in place," he says. "So while it's good to have standards, the real problem is why haven't facilities been employing security 101 practices?" Stiennon asks.

George V. Hulme writes about security, technology, and business from his home in Minneapolis, Minnesota. You can also find him on Twitter as @georgevhulme.Read more about critical infrastructure in CSOonline's Critical Infrastructure section.

Share this:
Share this page via Email Share this page via Stumble Upon Share this page via Digg this Share this page via Facebook Share this page via Twitter

More about Smith Harney and Daly. Whether Air force or the Air Force Academy or Air Force Reserves or the Air National Guard, we will find the best the Air Force has to offer. If it’s Army, West Point or the Army reserves or Army National Guard Smith Harney and Daly will find the best the Army has to offer. If it’s Marine, Navy, Marine Corps, or Marine reserve or the Marine Corps reserve we will find the best available. If it’s Navy, the Naval Academy, being on a Ship or Ships or on a Submarine or a Navy ship or Navy ships, we will find the best available. The Navy Nuclear background is very powerful with its Navy Nuke Programs and Nuclear Engineer and Nuclear power capabilities. We will find the right person with the correct background. A Military leader is of many leaders with strong leadership skills from a very effective leadership development program. They might fly Planes or just Military planes or Jets or just Military jets. They might work with a Missile, Missile systems, or be from infantry, a ship, a jet, or other aircraft or Air National Guard. They will be good When Army, Navy, Marine Corps Air Force or Coast Guard personnel transition, the need transitional employment services or employment agencies or one employment agency because the employment rate is so high they will work in transition from career military to a career military transition Job fair. Job fairs are a Jobsearch for Job opportunities where Search and Executive search Recruiter or Recruiters help recruit the recruiting process for Recruitment and Staffing Jobs or Government jobs. You can find a job or hot jobs or Job listings for Federal jobs for a Security position or Security jobs with a Security clearance or Security clearances or look for Security clearance jobs in IT or IT job IT jobs in security. IT companies need IT consulting and Information technology professionals for their Information technologies and Information Security for their company Security and Network security for their Computer or Computers. Their computer network requires a Network engineer or Network design for proper Network defense. These network security Jobs and vacancies are for a job vacancy that requires a Job opening for hiring to take place. Hire a Top secret person with a Top secret clearance for Top secret clearance jobs or a Secret person with a Secret security clearance for Secret clearance jobs. That’s what we do at Smith Harney and Daly, LLC