Full Report
Four governments just advised critical infrastructure operators to prepare to isolate their most important OT systems. Here’s what that means, who should care, and what to do about it. The post Multi-national CI Fortify Guidance at a Glance appeared first on Waterfall Security Solutions.
Analysis Summary
# Best Practices: Critical Infrastructure (CI) OT System Isolation
## Overview
These practices address the requirement for Critical Infrastructure (CI) operators to achieve "Operational Isolation"—the ability to disconnect vital Operational Technology (OT) and enabling systems from all other networks (IT, Cloud, and third parties) while maintaining the continuity of critical services during a cyber emergency.
## Key Recommendations
### Immediate Actions
1. **Identify Vital Systems:** Define the minimum set of OT assets, networks, and "enabling systems" (e.g., specific workstations or databases) strictly required to deliver the core critical service.
2. **Map All Interconnections:** Document every connection to vital systems, including corporate IT, vendor remote access, cloud services, and peer utilities.
3. **Establish Trigger Criteria:** Define specific conditions (threat levels or active compromises) that will mandate the immediate isolation of the OT environment.
4. **Secure Offline Backups:** Ensure isolation plans and critical system configurations are stored in an offline, immutable format.
### Short-term Improvements (1-3 months)
1. **Define Isolation Points:** Identify specific physical and logical points in the network architecture where connections can be severed without disabling the OT process.
2. **Address Non-OT Dependencies:** Identify IT-based dependencies (e.g., centralized DNS, Active Directory, or cloud-based licensing) that would cause OT to fail if isolated. Implement local, redundant versions of these services within the OT zone.
3. **Rank Critical Customers:** Identify "lifeline services" (e.g., hospitals, military bases) and set service delivery targets that must be met even during a period of total isolation.
### Long-term Strategy (3+ months)
1. **Hardware-Based Enforcement:** Transition from software-based segregation (VLANs/Firewalls) to high-assurance hardware (Unidirectional Gateways, Data Diodes, or Cross-Domain Solutions).
2. **Infrastructure Independence:** For distributed CI, move toward dedicated communication paths (e.g., private fiber or CWDM) rather than shared public infrastructure.
3. **Continuous Validation:** Implement a schedule for "Isolate-to-Operate" drills to ensure manual processes and local dependencies function as expected when the network is dark.
## Implementation Guidance
### For Small Organizations
- **Manual Isolation:** Focus on physical "pull-the-plug" procedures and manual workarounds.
- **Local Survival:** Prioritize keeping a local copy of all logic controllers (PLC) programs and critical documentation on-site.
### For Medium Organizations
- **Graduated Isolation:** Implement a tiered approach where non-essential remote access is cut first, followed by a total disconnect as threat levels rise.
- **Dependency Localisation:** Deploy localized versions of essential IT services (DHCP, NTP) within the OT perimeter.
### For Large Enterprises
- **High-Assurance Gateways:** Replace traditional IT/OT firewalls with Unidirectional Gateways to allow monitoring data *out* without allowing any attack path *in*.
- **Cryptographic Segregation:** If using shared links, implement robust, hardware-encrypted tunnels managed independently of the carrier.
## Configuration Examples
*While specific CLI code was not provided in the guidance, the following architectural configurations are recommended:*
- **Unidirectional Gateway:** Configure to replicate OT database tags to an IT-side mirror, ensuring the corporate office has visibility without a return path to OT.
- **Zone Grouping:** Group hosts into zones based on shared "criticality and trust" levels rather than physical location.
- **Local Service Redundancy:** Deploy an isolated Active Directory Forest or local DNS server specifically for the OT zone to prevent "IT-dark" failures.
## Compliance Alignment
- **CISA/FBI (USA):** CI Fortify Guidance.
- **ACSC (Australia), NCSC (UK), CCCS (Canada):** Joint Multi-national CI Protection.
- **NIST 800-82:** Guide to Industrial Control Systems (ICS) Security.
- **ISA/IEC 62443:** Security for Industrial Automation and Control Systems.
## Common Pitfalls to Avoid
- **Relying on VLANs:** Do not treat VLANs or MPLS as long-term isolation solutions; they are "minimally effective" against sophisticated pivoting.
- **Ignoring "Enabling Systems":** Forgetting that OT often needs specific IT-side services (like Windows Update Servers or License Servers) to stay operational for more than a few days.
- **Static Documentation:** Mapping connections once and never updating them; undocumented "shadow" connections are common entry points.
## Resources
- **CISA Guidance:** hxxps[://]www[.]cisa[.]gov/ (Search for CI Fortify)
- **Waterfall Security Self-Assessment:** hxxps[://]waterfall-security[.]com/lp/ot-network-isolation-self-assessment/
- **NIST OT Security Resource Center:** hxxps[://]csrc[.]nist[.]gov/projects/ics-security