Global Industrial Cyber Security Professional GICSP



Similar documents
Global Industrial Cyber Security Professional GICSP

ARC INDUSTRY FORUM 2015

WIB Mini-Seminar, The Hague (21 st of March 2013) An update from the Control Systems Working Group

Control System Integrity (CSI) Tools and Processes to Automate CIP Compliance for Control Systems

Session 14: Functional Security in a Process Environment

Vision & Positioning Statement For Wurldtech Labs

ABB Automation Days, Madrid, May 25 th and 26 th, Patrik Boo What do you need to know about cyber security?

Cybersecurity for Energy Delivery Systems 2010 Peer Review. Dale Peterson Digital Bond, Inc. Bandolier and Portaledge

ISA Security. Compliance Institute. Role of Product Certification in an Overall Cyber Security Strategy

CSSC-CL Announces ISASecure Certification of Hitachi and Yokogawa Industrial Control Devices. ~For More Globally Competitive Control System Devices ~

ISA Security Compliance Institute ISASecure IACS Certification Programs

The Next Generation of Security Leaders

ISA Security Compliance Institute

Best Practices in ICS Security for Device Manufacturers. A Wurldtech White Paper

How To Protect Water Utilities From Cyber Attack

Cybersecurity Guidance for Industrial Automation in Oil and Gas Applications

The Group CYTEK CYTEK PROJECTS CONSULTING

CYBER SECURITY Is your Industrial Control System prepared? Presenter: Warwick Black Security Architect SCADA & MES Schneider-Electric

Cyber Security & Compliance Briefing

Olav Mo, Cyber Security Manager Oil, Gas & Chemicals, CASE: Implementation of Cyber Security for Yara Glomfjord

EMC ACADEMIC ALLIANCE

Industrial Control Security

Approach to Information Security Architecture. Kaapro Kanto Chief Architect, Security and Privacy TeliaSonera

Cyber Security nei prodotti di automazione

ISA Security Compliance Institute

ICS Cyber Security Briefing

Industrial Cyber Security 101. Mike Spear

How Secure is Your SCADA System?

Emerson s Smart Wireless and WIB Requirements

Domain 1 The Process of Auditing Information Systems

Facilitated Self-Evaluation v1.0

Security Certifications. A Short Survey. Welcome. Stan Reichardt stan2007@sluug.org

Dr. Markus Braendle, Head of Cyber Security, ABB Group 10 Steps on the Road to a Successful Cyber Security Program Asia Pacific ICS Security SUMMIT

Release of the Draft Cybersecurity Procurement Language for Energy Delivery Systems

Supporting our customers with NERC CIP compliance. James McQuiggan, CISSP

Risk Management, Equipment Protection, Monitoring and Incidence Response, Policy/Planning, and Access/Audit

Business Overview of PRODML

Industrial Cyber Security Risk Manager. Proactively Monitor, Measure and Manage Cyber Security Risk

University of Central Florida Class Specification Administrative and Professional. Information Security Officer

Historians and Production Management as Cloud Applications

Roles within ITIL V3. Contents

SPSP Phase III Recruiting, Selecting, and Developing Secure Power Systems Professionals: Job Profiles

ARC VIEW. Industrial Defender and ABB Cyber Security Partnership Model. Summary. Cyber Security Strategies for Automation Suppliers.

Course 10750A: Monitoring and Operating a Private Cloud with System Center 2012

Does Aligning Cyber Security and Process Safety Reduce Risk?

Industrial Cyber Security. Complete Solutions to Protect Availability, Safety and Reliability of Industrial Facilities

GE Measurement & Control. Cyber Security for Industrial Controls

A Leading Provider of Engineering Information Management Solutions and Services. Facilitating multi-office, multi-contractor execution strategies

CYBER SECURITY. Is your Industrial Control System prepared?

Ernie Hayden CISSP CEH GICSP Executive Consultant

Security Solutions to Meet NERC-CIP Requirements. Kevin Staggs, Honeywell Process Solutions

Agenda. Introduction to SCADA. Importance of SCADA security. Recommended steps

COPYRIGHTED MATERIAL. Contents. Acknowledgments Introduction

The Critical Infrastructure: To be or not to be Secure. European Network for Cyber Security. Fred Streefland Director Education & Training

Critical Controls for Cyber Security.

Cyber Security Implications of SIS Integration with Control Networks

CENTRALIZED CONTROL CENTERS FOR THE OIL & GAS INDUSTRY A detailed analysis on Business challenges and Technical adoption.

RESILIENCE AGAINST CYBER ATTACKS Protecting Critical Infrastructure Information

ABB s approach concerning IS Security for Automation Systems

Cyber Risk Mitigation via Security Monitoring. Enhanced by Managed Services

Cybercrime & Cybersecurity: the Ongoing Battle International Hellenic University

Which cybersecurity standard is most relevant for a water utility?

Are you prepared to be next? Invensys Cyber Security

AUTOMATION AND PROCESS CONTROL

SCADA Security Training

Industrial Control System Cyber Security

Cyber security tackling the risks with new solutions and co-operation Miikka Pönniö

Best Practices in ICS Security for System Operators. A Wurldtech White Paper

COMPANY PROFILE- INDUSTRIAL DEFENDER

ESCoRTS A European network for the Security of Control & Real Time Systems

Cybersecurity Training

FOR REVIEW PURPOSES ONLY!

Is your current safety system compliant to today's safety standard?

ADVANCED DISTRIBUTION MANAGEMENT SYSTEMS OFFICE OF ELECTRICITY DELIVERY & ENERGY RELIABILITY SMART GRID R&D

Kevin Savoy, CPA, CISA, CISSP Director of Information Technology Audits Brian Daniels, CISA, GCFA Senior IT Auditor

PCN Cyber-security Considerations for Manufacturers. Based on Chevron Phillips Chemical Company PCN Architecture Design and Philosophy

1 ISA Security Compliance Institute

Process Automation and Instrumentation Market by Types, Technology, Application and by Geography - Analysis & Global Forecasts to

How to use the National Cybersecurity Workforce Framework. Your Implementation Guide

Industrial Cyber Security Risk Manager. Proactively Monitor, Measure and Manage Industrial Cyber Security Risk

Wireless Process Control Network Architecture Overview

MS 20247C Configuring and Deploying a Private Cloud

Transcription:

Global Industrial Cyber Security Professional GICSP A certification for Engineers, ICS Security Professionals, and ICS Technology Specialists ARC Industry Forum, Feb 10, 2014 SANS ICS Resources Control System Poster Webcasts ICS NewsBites STH Training Demo Follow us on Twitter @SANSICS www.sans.org/industrial-control-systems/resources/

GICSP = Global Collaboration The GICSP was developed and guided by a Steering Committee of leaders from major industrial companies, advisors, and suppliers from around the world. It includes members from the following companies/organizations: BP, Chevron, Pacific Gas & Electric, Shell, Saudi Aramco, ABB, Emerson, Invensys, Rockwell Automation, NIPSCO, KPMG, WurldTech, ERNCIP(JRC), TNO, SANS Institute, GIAC SME group (Engineering and security focused): Yokogawa, Schneider Electric (Telvent), Cimation, Cigital, Red Tiger Security, Honeywell The consortium of companies established collaboratively an open body of knowledge for the topic of ICS Security from which the certification framework and associated competency training programs could be established.

Collaborators

GICSP Subject Matter Experts Team including experts from ICS vendors, integrators, end-users and researchers: (job titles involved) Process control engineer Process control network cyber security engineer PCD IT security engineer Principal security architect Security architect ICS/SCADA security manager Regional technical authority Senior ICS/SCADA security consultant Head of process control security Director of reliability & security Senior security engineer Director of technology Developed by Engineers for Engineers and ICS Security Specialists

What is the GICSP? The GICSP is a new certification that focuses on the essential knowledge for professionals securing industrial technology. The GISCP has been developed for engineers, control system support, and security professionals who work in environments addressed by commonly accepted standards related to control system and automation security, including ISA-99/IEC 62443. Holders of the GICSP will demonstrate a globally recognized level of competence that defines the architecture, design, management, risk and controls that assure the security of critical infrastructure. The GICSP is the bridge to bring together IT, engineering and cyber security professionals to achieve security for ICS from design through retirement.

What is the GICSP? This certification establishes a base level of knowledge and understanding for the diverse set of professionals who engineer, operate, secure, or support control systems and share responsibility for the security of these environments. This certification is applicable to control system owner/operators across all sectors, ICS vendors, integrators, and support organizations, and professionals that have access to production industrial control systems from nuclear power plant systems to building automation. The GICSP is expected to be adopted on a global basis as a gateway certification for critical infrastructure-industrial control system professionals.

GICSP & Industrial Automation and Control Systems Cyber Security Certifications GICSP Standards Focused Certifications Automation Certifications (ISA-99) Functional certification aligned with performing industrial cyber security complimenting existing important and valuable certification efforts

GICSP Examination Highlights Examination 115 items (100 scored/15 non-scored beta questions); time limit of three hours Test delivery is computer based and proctored by Pearson VUE at over 4000 global testing centers Certification is valid for 4 years; continuing professional education requirements are consistent with GIAC standards see www.giac.org/renewal Certification Examination is available

GICSP Web Page http://www.giac.org/certification/global-industrial-cyber-security-professional-gicsp

See you in the control room!

Industrial Cyber Security Domains GICSP Certification Objectives: A. ICS Architecture B. ICS Security Assessments C. ICS Security Monitoring D. Configuration/Change Management E. Disaster Recovery and Business Continuity F. Incident Management G. ICS Security Governance and Risk Management H. Physical Security I. Industrial Control & Automation Systems J. ICS Modules and Elements Hardening K. Cyber Security Essentials for ICS L. Access Management