A senior technology auditor has raised concerns about his profession's awareness of the risks posed by critical infrastructure operators' shift from proprietary systems to open standards-based structures for the management of important tasks.

Certified information systems auditor (CISA) Barry Munns told Builder AU sister site ZDNet Australia the IT auditing profession had "largely ignored" moves by energy, gas and water utilities to adopt open standards for their telemetry and telecontrol infrastructure, often known as supervisory control and data acquisition (SCADA) systems and the dangers this created. These systems allow remote control or monitoring of infrastructure, such as substations or water pipes.

"There's a bit of a generational change that's happening," Munns said.

"Moving away from fairly closed system, proprietary type structures -- software and operating systems, to more open systems or public type systems. All the risks associated with things like hacking and denial of service, those risks are now very much coming to the fore in SCADA."

Munns has audited such systems for Energy Australia, and recently joined the Australian Nuclear Science and Technology Organisation (ANSTO).

"SCADA telemetry and telecontrol systems are moving towards that open arrangement and that inter-connected kind of model," he said.

"As an IT auditor, it's an area that's largely ignored and generally not known about.

"I think it's an area that doesn't have a great deal of profile in my profession."

While attackers would previously have had to have a high degree of specialised knowledge and sometimes physical access to the critical infrastructure operators' facilities to wreak havoc, now there task was a lot more simple, according to Munns.

"Whereas before you might have had a very much closed system, a proprietary SCADA system that you bought from a company and they gave you all the hardware and software ... and it was very unique to that arrangement.

"Nowadays, you might buy a SCADA system or develop a SCADA system but you might be using Linux as your operating system, you might be using TCP/IP as your communication protocol, you might be using generally available firewall software. So all of a sudden you're using stuff that is common. And because it's common, it's more exposed.

"So whereas before there might've only been a very small number of people who knew about this stuff ... we're actually moving to an area where you don't have to be an insider anymore. That's where the problem arises."

This greatly increased the number of potential attackers, Munns said.

"Often you needed physical access to these things to be able to get up to no good, well that level of security has been done away with as we move towards open standards."

Munns said more organisations needed to adopt IT governance frameworks in order to realise the risks.

"I'd strongly recommend the application of 7799 Information Security standard, in any organisation," he said.

The federal government last year published advice for chief executive officers on SCADA systems, and runs security forums such as the Trusted Information Sharing Network (TISN) to deal with the risks.

Munns declined to comment on Energy Australia's SCADA systems.

Related links

Comments

1

Taggart Bradbury - 07/11/07

This dude is a moron.
I have a master's degree in computer science - I think that qualifies me as something other than "IT Ignorant" as Mr. Munns put it.
Is he somehow trying to argue that proprietary systems are inherently secure??!! HAHAHAHAHAHAHAHAHAAH:)
Seen any Windows hacks lately?
LINUX has NEVER, in its history - and last I check the UNIX operating system has been around waaaaaaaay longer than Windows - had a virus successfully propogate.
The lack of viruses and trojans and worms - and security problems in general - has nothing to do with how many LINUX boxes there are.
It's because the UNIX KERNEL IS SECURE, dumbass.
And by the way, how many servers are out there running LINUX?
More than are running Windows, that's for sure.
This guy is the one who is "IT ignorant".

» Report offensive content

Leave a comment

You must read and type the 6 chars within 0..9 and A..F

* indicates mandatory fields.

1

Taggart Bradbury - 11/07/07

This dude is a moron. I have a master's degree in computer science - I think that qualifies me as something other ... more

Log in


Sign up | Forgot your password?

  • Staff Microsoft shows off IE9 preview

    This week, highlights from Microsoft's MIX10 conference and more in the Roundup. Read more »

    -- posted by Staff

  • Chris Duckett IE9's H.264 vote killed Ogg

    In a split decision by the judges, the winner of the W3C/WHATWG video codec consensus is H.264, taking home the future of video playback on the internet while loser Ogg goes home with nothing but thoughts of what might have been. Read more »

    -- posted by Chris Duckett

  • Staff Google launches Apps Marketplace

    Google launches and app store, while Mozilla plans to re-write its open-source license. More of this week's news in the Roundup. Read more »

    -- posted by Staff

What's on?

  • Optus Deal

    Broadband + home phone + PlayStation®3 in a single package price!