Authors:
Luca Pöhler
;
Marko Schuba
;
Tim Höner
;
Sacha Hack
and
Georg Neugebauer
Affiliation:
Department of Electrical Engineering and Computer Science, FH Aachen University of Applied Sciences, Eupener Str. 70, 52066 Aachen, Germany
Keyword(s):
OT, ICS, OT Security, Risk Management, Asset Management, Asset Discovery, Asset Inventory.
Abstract:
The need for compliance and the growing number of IT security threats force many companies to improve their level of IT security. At the same time, new legal regulations and the trend to interconnect IT with automation environments (operational technology, OT) lead to the situation that IT security and OT security need to be approached at the same time. However, OT differs from IT in several aspects and many well-established IT security procedures cannot simply be copied to OT networks. As in IT the first step to establish an acceptable security level for OT is to perform a proper risk assessment. Available tools that support OT asset management are either expensive or they do not provide the functionality needed. In the context of this paper a new open-source approach to OT asset management is presented. The tool that was developed to collect OT assets considers the specific characteristics of OT devices, the sensitivity of production environments, and the typically rudimentary star
ting situation of many real-world machine operators while being free of charge at the same time.
(More)