SESSION ID: PS-F01 SDLC and 62443: Build It In, Don’t Bolt It On Shoshana Wodzisz Global Product Security Leader Rockwell Automation @slwodzisz #RSAC #RSAC Presenter’s Company Logo – replace or delete on master slide #RSAC Presenter’s Company Logo – replace or delete on master slide #RSAC What is IEC 62443? Series of global standards that define requirements for implementing electronically secure Industrial Automation and Control Systems (IACS). It covers the entire lifecycle of a product. In other words: Customers care because: Presenter’s Company Logo – replace or delete on master slide International Standard Cybersecurity Industrial Control Systems Globally recognized standard Independently certified They now know what to ask for 4 #RSAC IEC/ISA 62443 Defense in Depth Presenter’s Company Logo – replace or delete on master slide Risk Transference 5 How do companies start on the security journey ? Extra time they don’t know what to do with Value process over delivering products Love paying taxes Idolize Microsoft and their SDLC Industry standards Customer requests Presenter’s Company Logo – replace or delete on master slide 6 #RSAC We started using the “Bolt On” method Presenter’s Company Logo – replace or delete on master slide 7 #RSAC To add Security to your Development Process …. You must have development processes to start with We do have development processes…..lots of them !! We found that they were essentially all the same. Presenter’s Company Logo – replace or delete on master slide 8 #RSAC #RSAC Our SDLC Evolution #RSAC Started with a Framework Management Concept Development Utilization Production (Install, Commission, Validate, Operate, Maintain, Repair) Support (Modify, Retrofit, Support) Disposal Product Lifecycle: Concept  Disposal not just “development” ISO/IEC 15288:2015 Systems and Software Engineering System Life Cycle Processes Presenter’s Company Logo – replace or delete on master slide 10 #RSAC Processes in the Framework Reviews, Audits, Supply Chain, Skills/Training, Dev Environment, Governance Management Concept Requirements Presenter’s Company Logo – replace or delete on master slide Development Production Design Assess Risk Implement/Code Test Assess Risk Threat Modeling Configuration Mgmt. Release Utilization (Install, Commission, Validate, Operate, Maintain, Repair) Support (Modify, Retrofit, Support) Incident Response Metrics ISO/IEC TR24774 Systems and software engineering – Life cycle management – Guidelines for process description. Disposal #RSAC Defined the processes Leveraged 24774 as guidance to developing a process Focused on activities and tasks Created a process template for the teams to use Wrote processes based on industry and internal best practices Etc. ISO/IEC TR24774 Systems and software engineering – Life cycle management – Guidelines for process description. Presenter’s Company Logo – replace or delete on master slide 12 #RSAC Ideas & Theories Management Concept We really started here Just above the details Development Production Utilization (Install, Commission, Validate, Operate, Maintain, Repair) Support (Modify, Retrofit, Support) Disposal Frameworks Consistent Processes The Nitty Gritty Engineering Details Presenter’s Company Logo – replace or delete on master slide #RSAC How we really built security in #RSAC Cultural “Experiences” “We already do this today – just clean up a few processes and get them certified!” “Make sure all groups have a voice and buy-in” “We do development differently than all other groups in the company – our products are different” “We already have processes, let me show you my 8 tab excel checklist.” “We have a stage gate process. Get it – it’s our process !” Presenter’s Company Logo – replace or delete on master slide 15 #RSAC Company Policy Security is not optional. Processes Activities and tasks (IEC TR 24774) Templates Consistency in outputs Job Aids Work Instructions Procedures How we do our work Things we often forget Checklists Presenter’s Company Logo – replace or delete on master slide 16 A note on process development #RSAC Besides understanding what a Process is, these specific areas continue to trip people up – Outcome of a Process – what would it look like if the process were successfully executed? Not: The design is signed off Yes: Multiple design options are considered, documented, and communicated to help ensure that fu

pdf文档 2020_USA20_PS-F01_01_SDLC and 62443 Build it in dont bolt it on

安全研究库 > 国外研究报告 > 产品安全性 > 文档预览
24 页 0 下载 23 浏览 0 评论 0 收藏 3.0分
温馨提示:如果当前文档出现乱码或未能正常浏览,请先下载原文档进行浏览。
2020_USA20_PS-F01_01_SDLC and 62443 Build it in dont bolt it on 第 1 页 2020_USA20_PS-F01_01_SDLC and 62443 Build it in dont bolt it on 第 2 页 2020_USA20_PS-F01_01_SDLC and 62443 Build it in dont bolt it on 第 3 页 2020_USA20_PS-F01_01_SDLC and 62443 Build it in dont bolt it on 第 4 页 2020_USA20_PS-F01_01_SDLC and 62443 Build it in dont bolt it on 第 5 页
下载文档到电脑,方便使用
还有 19 页可预览,继续阅读
本文档由 张玉竹2022-04-08 09:36:48上传分享
给文档打分
您好可以输入 255 个字符
安信天行文库的中文名是什么?( 答案:安信天行 )
评论列表
  • 暂时还没有评论,期待您的金玉良言