Module 8: Remediation
This module covers how to control risk to the network through appropriate remediation techniques. It introduces the concept of the Security Design Life Cycle (SDLC) and the importance of building security in at initiation, rather than “bolting” it on afterwards. In ICS and other SCADA systems, this may not be possible. Foundation guidelines and policies for controlling risk and personnel behavior will be addressed. An enumeration of network protection systems will be provided, including firewalls, intrusion detection systems (IDS), and intrusion prevention systems (IPS).
The module discusses the importance of digital signatures to providing device authentication, and how vulnerabilities specific to ICS systems relate to remediation techniques. Additionally, it covers common vulnerabilities found in ICS systems and techniques to identify vulnerabilities, as well as remediation techniques.
- Describe how risk management techniques control risk.
- Explain the concept of the Security Design Life Cycle (SDLC).
- List the types of security policies and how these relate to remediation.
- Describe how awareness and training can provide increased security.
- Identify remediation techniques in an ICS network, including routers, firewall technology, and tools for configuring firewalls and routers.
- Describe intrusion detection and prevention systems and web-filtering technologies.
- Explain the importance of digitally signed code for pushes of firmware and other updates to automated devices.
- Demonstrate the ability to evaluate and assess vulnerabilities in ICS networks.
- Explain and make recommendations for remediation strategies in an ICS network.
- Describe the hazards (do and don’ts) of the corporate network process vs. ICS network process.