Skip to content

CIS Controls Version 8: Learn what changes with Engine Advancements

This May, the Center for Internet Security (CIS) has launched version 8 of the security control tool for critical systems, especially marked by structural progress aimed at cloud and mobile environments. The concentration of online tasks and the remote work model are becoming increasingly popular due to mobility restrictions caused by the pandemic, which generates, proportionally and positively, technological evolution to ensure the execution of work, social and entertainment activities.

What Is Different?

 CIS Controls v8 is based on the activities performed, not on the user who controls the devices or on the devices themselves. Whereas previous versions focused on a centralized network that grouped all coordination and security endpoints, version 8 tracks virtual changes and assimilates new cyberattack modalities based on real threats cited in Verizon’s 2021 Data Breach Investigations Report.

 Until the previous version (7.1), the set consisted of 20 main controls and 171 sub controls, but the modernization of the system condensed the total to 18 controls and 153 safeguards (yes, the term has also changed!) divided into 3 Implementation Groups (IGs), which work as a practical guide to help organizations of all sizes with their particular needs and to adapt them to current regulations. 

 As IG1 is the primary Implementation Group, every company needs to start with it, as it is considered the set of “basic cyber hygiene” and serves to preserve the information system from the most recurrent attacks. In the current version, it supports 56 safeguards in total, while IG2 has 74 and IG3 has 23 safeguards, making up the complete package.

To ensure essential protection, the following controls must be adopted: 

4: Secure configuration of company assets and software

5: Account management

6: Access control management

14: Security awareness and skills training

 

v8 Extra Points: 

CIS CSAT Pro self-assessment capabilities, with location tracking, optional data sharing, separation of roles and user behavior;

Community Defense Model (CDM) v2.0, with safeguards mapping and consultation of reports released by the industry, which indicate the main threats and frequent attacks;

CIS Controls Mobile Companion Guide and CIS Controls Cloud Companion Guide, which are guides for implementing CIS security best practices for mobile devices such as mobile phones and tablets; and for cloud environments, respectively.

What Does the Launch of Controls v8 Mean? That CIS understood the defense priorities of the critical data environment and streamlined the cybersecurity process. For businesses, the result is the quality of critical system security options and the practicality of complying with regulatory data protection requirements (PCI-DSS, SOx, HIPAA, and others).

Source: https://www.cisecurity.org/blog/18-is-the-new-20-cis-controls-v8-is-here/

Text: Priscilla Silva

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

NERC Develops Practice Guide to Help Organizations Evaluate Network Monitoring Technologies

Earlier this month, on June 4th, the North American Electric Reliability Corporation (NERC) released a new practice guide that pinpoints how organizations should integrate network monitoring solutions into industrial operational technology (OT) networks of the electric utility industry.

NERC developed the ERO Enterprise CMEP Practice Guide: Network Monitoring Sensors, Centralized Collectors, and Information Sharing in response to the Department of Energy’s (DOE’s) 100-day plan. The Department of Energy’s initiative is to advance technologies that provide increased visibility, detection, and response capabilities for utilities’ industrial control systems (ICS) and operational technology (OT) networks to better protect the nation’s agencies and infrastructures.

While many government agencies and organizations have already deployed these types of technologies within their OT environments, the NERC anticipates an increase in deployments across the electric utility industry to increase threat detection and incident response abilities due to the DOE 100-day plan. NERC provides an actionable framework for auditing compliance with the CIP Reliability Standards when a registered entity deploys detection and monitoring technologies that include network monitoring sensors and centralized data collectors and may involve the sharing of data collected with third parties.

Additionally, the guide provides ERO Enterprise examples of how to comply with industry standards. This is super helpful as the NERC is aiding organizations with the right framework with compliance monitoring when it relates to the deployment of OT security technology.

We’ve put together an overview of the report and the key takeaways that relate to OT security.

Protecting Cyber Assets

As expected, the guide discusses the importance of the protection of cyber assets. According to NERC, the CIP standards require registered entities to protect Bulk Electric System (BES) Cyber Systems and certain associated Cyber Assets.

For organizations to get a better understanding in the manner in which the CIP standards apply to network monitoring deployments is to determine whether the sensor to be deployed is a Cyber Asset, BES Cyber Asset, and then a BES Cyber System or other types of Cyber Asset subject to requirements of the CIP standards, such as a Protected Cyber Asset (PCA) or Electronic Access Control or Monitoring System (EACMS).

If a sensor does not qualify as a BES cyber system, it may be categorized under CIP requirements depending on how it is used and which environment it is deployed in. Devices that are deployed in high or medium impact can be categorized as protected cyber assets if they are inter-connected with routable protocols within an electronic security perimeter or as electronic access control or monitoring systems (EACMS).

The report ended the section about protecting cyber assets by saying that organizations may not be required to secure sensors that are deployed in an environment with only low-impact BES cyber systems even if they are “performing the functions of an EACMS or other device subjects to the CIP standards.” However, auditors must still assess whether those devices are subject to the requirements of CIP-003-8 concerning electronic access control.

Data Protection with 3rd Parties Access

The report mentions when it comes to the protection of data, the CIP standards require that organizations need to control access to BES cyber system information (BCSI). According to NERC, “Information about the BES Cyber System that could be used to gain unauthorized access or pose a security threat to [it].” The report provided different examples of such data including network topology of the system, security procedures, collections of network addresses, and any information that is not publicly available and could be used to allow unauthorized access or distribution of sensitive data.

NERC recommends that Compliance Monitoring and Enforcement Program (CMEP) teams are urged to identify how their organization determines whether the data collected by its sensors contains BCSI and whether the information is transmitted and accessible by third parties. If BCSI is included in the data, organizations must assess whether the utility has a process in place to authorize access to the designated storage locations for BCSI. Additionally, any potential third-party access to information needs to be also accessed.

The guide also recommends that CMEP teams fact-check a utility’s network monitoring technology deployment by implementing a deep dive review of every system to ensure that no possible vulnerabilities are missed.

Governance for OT Networks

This NERC report is a very detailed framework which industrial organizations especially in the US electric community will start to implement. We expect government agencies to use this guide as a compliance framework for all discussions on passive monitoring technology.

The SCADAfence Platform for OT security, combined with the SCADAfence Governance Portal, helps utility companies ensure that their Bulk Electric System (BES) is secure and reliable according to the North American Electric Reliability Corporation critical infrastructure protection (NERC CIP) standards. The SCADAfence Governance Portal includes a built-in NERC CIP module which provides cross-organizational tracking and measurement of NERC CIP adherence.

To learn how your organization can achieve NERC CIP compliance by using the SCADAfence Governance Portal, download the full whitepaper here: https://www.scadafence.com/resource/nerc-cip-compliance-scadafences-unique-solution-whitepaper/

Having visibility into compliance enables IT and OT departments to centrally define and monitor their organization’s adherence to OT-related regulations and security policies. To learn more about IT & OT compliance, please join us on June 23rd for our joint webinar with Rapid7 as we will cover how to measure compliance over time for standards such as NIST, NERC-CIP, IEC-62443, among others.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.