Air gaps have been ‘shattered’, says new Indian policy on power sector security

India has announced a new security policy for its power sector and specified a grade of isolation it says exceeds that offered by air gaps.

“The much hyped air gap myth between information technology (IT) and operational technology (OT) systems now stands shattered,” the policy states, before going on to offer a slightly odd definition of an air gap.

“The artificial air gap created by deploying firewalls between any IT and OT system can be jumped by any insider or an outsider through social engineering.”

India’s answer is … something that sounds a lot like an actual air gap.

The first item in the new policy is “hard isolation of their OT systems from any internet facing IT system”.

Power sector players – generators, transmission utilities and distributors – have a requirement of “only one of their IT systems with internet facing at any of their sites/locations, if required, which is isolated from all OT zones and kept in a separate room under the security and control of CISO,” referring to the chief information security officer.

The policy also requires any activity on the sole internet-connected system to be done “through an identifiable whitelisted device followed by scanning of both for any vulnerability/malware”. Even that device can only connect to whitelisted IP addresses.

If the OT kit at a power player must communicate with the outside world, it should happen over optic fibre and preferably over POWERTEL – a carrier operated by government owned electricity transmission company Power Grid Corporation of India.

One item in the policy to watch is the requirement to use only products deemed to come from “trusted sources”, as that list appears not to have been created before the policy directive was issued. What’s the bet anything made in China isn’t on the list?

The policy also requires all operators of power infrastructure to create an Information Security Division, appoint a CISO to lead it, and ensure compliance with security advisories issued by CERT-IN – including prompt application of patches.

Lifecycle management of all kit is also required, with replacements ordered for any out-of-support products. That new kit must be certified against the Common Criteria standards.

The policy applies to system integrators, equipment manufacturers, and even hardware and software OEMs that serve India’s power supply system. As India has undergone rapid electrification in recent years, under a plan to bring electric power to the entire nation, such suppliers have had huge growth opportunities.

The new policy implies that some of the entities involved in operating the resulting network of generation and transmission infrastructure might not be in the best of shape. Hopefully the document’s debut doesn’t provide an incentive to attackers. ®

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Car key can stay at home if you have a Samsung Galaxy thumbnail

Car key can stay at home if you have a Samsung Galaxy

Auteur: RubenPriest, gepost 1 oktober 2021 om 08:30 – Reageer De Samsung Galaxy smartphone vervangt je ouderwetse autosleutel. Scheelt weer ruimte in je broekzak! Portemonnee, al die pasjes, sleutels. Je smartphone neemt steeds meer zaken over, waardoor je meer dingen thuis kunt laten. Zo ook de de autosleutel. Diverse autofabrikanten, zoals Tesla en BMW, maken…
Read More
Samsung launches new environmentally friendly TV remote control: In addition to direct light, it can also get power from WiFi thumbnail

Samsung launches new environmentally friendly TV remote control: In addition to direct light, it can also get power from WiFi

据悉,三星已经从其环保遥控器中淘汰了电池替代品。去年这家公司新增了一个太阳能电池板,现在它正在升级其2022年产品--将能从家里的无线电波中收集能量。2022年的三星环保遥控器(Samsung Eco Remote)仍可以通过把它放在直射光下进行充电,除此之外,它还可以使用来自WiFi路由器或其他无线源的射频能量。 射频能量采集听起来有点像低调的魔术,但它实际上是一项相当成熟的技术。它依赖于将电磁能--如你的WiFi路由器或其他设备产生的电磁能--转化为直流电能,然后小型电子产品就可以使用。不过在这里,谈论的数量相对较少,而这实际上也正是遥控器的实际电力需求。三星虽然没有说2022年的这款遥控器在单独使用射频能源的情况下可以持续的时长,但太阳能和射频采集的结合应该意味着用户伸手去拿遥控器却发现它没电的情况会变得少得多。与此同时,对于2022年的更新产品还有一个审美上的变化。三星现在将提供白色版本的遥控器和黑色版本的遥控器从而更好地匹配其一些生活方式的电视。除了D-pad、音量、语音控制和其他快捷键外,还有专门的启动按钮用于关键的按需服务。三星TV Plus、Netflix、Amazon Prime Video和Disney+。这是三星和其他公司正在推动的减少浪费的一部分,尤其是在配件和包装方面。如新的遥控器使用了一个超级电容器(SuperCap)而非电池,所有2022年的电视都减少了电力消耗。在包装方面,现在更多地使用的是可回收材料。EPS垫、塑料带、夹子、支架袋和盒子支架现在都是由回收的纸板和塑料制成且没有钉子将盒子本身固定起来。这不仅仅是对环境的好消息,另外,三星还表示,通过取消金属紧固件,它现在可以在1秒内组装好一个电视盒,而使用旧系统则要5秒。如果说有什么缺点的话,那就是三星一方面为减少浪费和功耗所做的努力可能会被其在NFT方面的努力所抵消。如今,NFT成为了一种时尚,三星也正在其2022年的电视中打造一个NFT聚合平台。这将有一个探索器和市场聚合器,这样用户就可以浏览所提供的NFT艺术品、阅读背景资料、购买它们,然后让电视自动调整其设置以显示它们的最佳状态。不幸的是,仍没有真正的方法来解决NFT艺术涉及的电力需求,特别是当涉及到挖掘通常用于支付的加密货币时。CrytpoArt.wtf是一个估算一些高调的NFT艺术品销售所涉及的能源消耗的网站,在对18000件NFT的分析中发现,平均而言,它们的碳足迹相当于一个生活在欧盟的人一个月的用电量。网站创建者Memo Akten指出,CrytpoArt.wtf在被当做虐待和骚扰的工具后被关闭。
Read More
OpenSSF启动Alpha-Omega项目 提高开源软件安全 thumbnail

OpenSSF启动Alpha-Omega项目 提高开源软件安全

为进一步改善开源软件(OSS)的安全现状,OpenSSF 今天宣布启动 Alpha-Omega 项目,从而让软件安全专家直接参与和执行自动安全测试。该项目已经获得了 500 万美元的启动资金,并得到了包括微软、Google 在内的诸多科技巨头的支持。 OpenSSF 总经理 Brian Behlendorf 表示:“我们必须认识到开源软件是现代社会关键基础设施的重要组成部分,因此要采取一切必要措施来保证它和我们的软件供应链的安全。Alpha-Omega 以公开和透明的方式支持这一努力,通过主动发现、修复和预防漏洞,直接提高开源项目的安全性。这是我们 OpenSSF 希望成为改善开放源代码安全的主要渠道的开始”。Alpha-Omega 项目试图通过“系统地寻找开放源代码中尚未发现的新漏洞,然后与项目维护者合作,使其得到修复”,来提升全球开放源码软件供应链的安全性。微软 Azure 的首席技术官 Mark Russinovich 表示:“能支持 OpenSSF 和 Alpha-Omega 项目,我们感到非常自豪。开源软件是我们技术战略的一个关键部分,我们必须了解伴随着我们所有的软件依赖的安全风险。Alpha-Omega 将通过与维护者的直接接触以及使用最先进的安全工具来检测和修复关键的漏洞,为关键的开源项目提供保证和透明度。我们期待着与行业伙伴和开源社区就这一重要举措进行合作”。该项目中的 Alpha 将帮助最关键的开源项目(包括独立项目和核心生态系统服务)的维护者识别和修复安全漏洞,并提升其安全态势。这些项目将根据 OpenSSF 保障关键项目工作组的工作,在专家意见和数据的帮助下进行选择。而 Omega 则确定至少 10,000 个广泛部署的开放源码软件项目,在这些项目中,它可以将自动安全分析、评分和补救指导应用于其开放源码维护者社区。Omega 软件工程师团队将调整分析管道,以减少假阳性率并检测新的漏洞。
Read More
Index Of News
Total
0
Share