Browse Definitions :
Definition

ICS security (industrial control system security)

Contributor(s): Matthew Haughn

ICS security is the area of concern involving the safeguarding of industrial control systems, the integrated hardware and software designed to monitor and control the operation of machinery and associated devices in industrial environments.

Industrial control systems are used in machinery throughout a wide range of industries all around the world. The systems monitor, manage and administer everything from nuclear power plants and other utilities to HVAC installations, robotics and even prison cell doors.

Historically, these systems were not networked and lacked computing and communications technologies. A major focus of the burgeoning Internet of Things (IoT) – and the Industrial IoT in particular – is networking non-computing devices and making it possible for them to exchange data over the Internet. Although industrial control systems may not themselves be connected to the Internet, the human-machine interfaces (HMI) through which they are managed typically are.     

Industrial systems, including critical infrastructure, are increasingly being networked and outfitted with computing and communications technologies. The trend to IT/OT convergence means that systems used for data-centric computing -- IT systems -- are being integrated with the operational technology (OT) systems used to monitor events, processes and devices and make adjustments in enterprise and industrial operations.

Ironically, because ICS often support critical infrastructure, they cannot easily be taken down for security updates and so often remain unpatched and vulnerable. Furthermore, because the systems have very limited computing resources, they often lack the capacity to run antimalware software.

 See a SANS webinar on ICS security:

This was last updated in March 2016

Continue Reading About ICS security (industrial control system security)

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

-ADS BY GOOGLE

File Extensions and File Formats

Powered by:

SearchCompliance

  • risk management

    Risk management is the process of identifying, assessing and controlling threats to an organization's capital and earnings.

  • compliance as a service (CaaS)

    Compliance as a Service (CaaS) is a cloud service service level agreement (SLA) that specified how a managed service provider (...

  • data protection impact assessment (DPIA)

    A data protection impact assessment (DPIA) is a process designed to help organizations determine how data processing systems, ...

SearchSecurity

  • cybersecurity

    Cybersecurity is the protection of internet-connected systems -- including hardware, software and data -- from cyberattacks.

  • encryption

    Encryption is the method by which information is converted into secret code that hides the information's true meaning. The ...

  • computer worm

    A computer worm is a type of malicious software program whose primary function is to infect other computers while remaining ...

SearchHealthIT

SearchDisasterRecovery

  • business continuity plan (BCP)

    A business continuity plan (BCP) is a document that consists of the critical information an organization needs to continue ...

  • disaster recovery team

    A disaster recovery team is a group of individuals focused on planning, implementing, maintaining, auditing and testing an ...

  • cloud insurance

    Cloud insurance is any type of financial or data protection obtained by a cloud service provider. 

SearchStorage

Close