Tying Bow Ties: From PHA To The Cloud

No ratings

Presented at s4x17 2017 by

Bow Tie risk assessment methodology has traditionally been used to analyze safety, but more recently, cyber threats have made their way into the analysis. OSIsoft has adapted the Bow Tie methodology to examine the cyber profile of their software installations. By chaining Bow Tie diagrams together, this methodology can visualize the cyber footprint throughout a network to effectively enumerate defenses at each layer, and consequences downstream of initial compromise. In this session, we will start with a PHA through Bow Tie analysis, incorporating cyber threats along with traditional physical threats. Through the chaining of the Bow Tie diagrams, we will visualize how compromises of cyber assets upstream of the control network lead to physical impacts downstream. More importantly, we will show how this approach allows defenders to organize defenses at each layer, and put them into the context of the whole system. Each member of the team is able to drill into the component under their jurisdiction for actionable information and observe the entire chain to understand their role within the larger system. This provides a common language for operators, ICS security leads, IT administrators and DBAs while allowing each to focus on what is actionable to their group.