Thread Content
In recent years, the economic and information technology departments have been urging that industrial control security inspections be carried out in accordance with the requirements of the Cybersecurity Law and the Guidelines for Information Security Protection of Industrial Control Systems. These inspections cover aspects such as the selection of security software, configuration and patch management, remote access, identity authentication, security monitoring, border security protection, as well as emergency response plans and drills. How exactly does everyone carry out work on information security for industrial control systems? Should an external company be invited, or be it carried out internally? Is it partially compliant with the requirements of the Guidelines, or is it fully compliant? What are the steps and contents of the work to be carried out? (For example: whether industrial host protection devices are installed, whether mechanisms for preventing virus and malware intrusions have been established, whether network security policies for industrial control systems are in place, whether logical isolation exists between different security zones, whether network security monitoring devices are deployed, and whether protection devices with deep packet analysis and filtering capabilities are in use?) etc.)
Does your process control network (i.e., the control layer network) connect to the external network? If there is no connection to the external network, it’s only necessary to monitor the insertion and removal of storage devices such as USB ports; nothing else matters~!
Industrial automation control systems – if they are not connected to the external network, then they have absolutely no relevance to information security at all. Of course, if Americans, Japanese, or whoever embed spy programs in those tiny chips used in sensor boards, they can use satellites to remotely activate those programs and cause trouble. Ugh… Then your cries about the security of industrial automation are nothing but nonsense. Why? First, your so-called experts aren’t capable of detecting those spy chips; second, your brilliant experts can’t block satellite signals; and third, us weaklings can’t help your security experts at all. {:2_42:}
The United States develops some kind of system, and you experts immediately try to learn how to use that system. For example, with SIS, you learn to use it even faster than a dog licking its own excrement. But what if one day, a malicious satellite belonging to the Americans sends out a harmful signal that alters the settings of SIS, thereby causing all the tanks in our chemical plants to explode? What would we do then? I’m so worried about your security experts – they’re inviting trouble in, which is extremely unreliable...........
There are increasingly more inspections by the administrative authorities nowadays, and safety is also an important requirement for companies themselves; however, there are still too few cases at present.
Install a firewall and antivirus software, add a USB drive lock, remove the optical drive, and so on