The US Cybersecurity and Infrastructure Security Agency (CISA) and Australia’s Cyber Security Centre (ACSC) have collaboratively released a comprehensive guide aimed at helping critical infrastructure organizations isolate essential operational technology (OT) and supporting systems. This initiative is designed to enhance the cyber resilience of critical infrastructure, ensuring that vital services remain uninterrupted during crises.
Strengthening Cyber Resilience Against Threats
The guidance document, titled CI Fortify – Advice for Isolating Vital Systems, provides detailed instructions on how these crucial systems can be maintained in isolation for extended periods. This is crucial for the continuity of critical services amidst potential disruptions. The primary focus is on improving the preparedness, response, and recovery strategies of OT owners, operators, and cybersecurity teams.
According to the guidance, CI operators need to develop the capability to isolate critical OT and enabling systems from other networks. This isolation can disrupt the plans of malicious cyber actors, contain active incidents, and facilitate the safe rebuilding of compromised systems. Identifying all systems and networks that support critical services, as well as understanding the dependencies that customers have on these infrastructures, is the recommended first step.
Implementing Isolation Strategies
To manage risks effectively, organizations should identify common levels of criticality and trust for systems and networks, subsequently segmenting them into zones. This classification aids in better risk management and control application. Once systems are identified and categorized, it is essential to document and regularly update technical information regarding connections between critical and non-critical systems, including vendor access, untrusted networks, and cloud environments.
The guidance also emphasizes that system isolation will necessitate manual processes and may disrupt system-to-system communications, impacting upstream dependencies and peers. Therefore, organizations are encouraged to work closely with affected partners to address critical dependencies as part of isolation planning. Establishing effective separation points between critical and non-critical networks is also crucial to limit threat actors’ access and facilitate containment and remediation efforts.
Maintaining Business Continuity
Organizations are advised to incorporate physical isolation points within vital systems, enabling operations to continue independently from other networks. Developing a graduated isolation plan that allows progressive isolation of pathways while maintaining business continuity is also suggested.
Monitoring the effectiveness of isolation mechanisms throughout the isolation period is crucial to ensure no unauthorized connections occur between critical and non-critical networks. Additionally, the guide highlights operational and security risks associated with the adoption of CI Fortify, such as reduced patching capabilities and increased infection risks from removable media. Organizations are advised to consider these factors when operating in isolation.
Further resources and detailed guidance can be accessed on CISA’s CI Fortify: Strengthening Resilience Across Critical Infrastructure page.
