Air Gaps, Firewalls and Data Diodes in Industrial Control Systems
Nexor have just released a briefing paper Air-Gaps, Firewalls and Data Diodes in Industrial Control Systems looking the issues around segregating industrial control system networks. What works best: Air Gaps, Firewalls or Data Diodes?
The answer is of course, it depends.
Segregation is used to prevent the spread of malware that could stop an industrial process running, or cause a safety issue. The purpose of the paper is to ensure that Data Diodes are considered as part of the tool kit when a solution architect is looking at how to segregate systems. Data diodes are not always the right answer; air gaps and firewalls have their place too – the important part is that an informed choice takes place.
The paper is aimed at the business manager, giving only brief details on some of the more technical points. In the coming weeks, I will blog on specific technical issues raised in the briefing paper to explore them further.
- Overcoming Air Gap Security Failures
- Data Diode Technology Can Help Solve Complex Cyber Security Issues
Having read the briefing, please let me have your comments and view on the issues raised below.
This article was originally posted on the Cyber Matters blog – which gives “bite-size insight on cyber security for the not too technical”.
Author Bio - Colin Robbins
Colin Robbins is a Principal Security Consultant at Nexor. He is a Fellow of the IISP, and a NCSC certified Security and Information Risk Adviser (Lead CCP). He has specific technical experience in Secure Information Exchange & Identity Systems and is credited as the co-inventor of LDAP. He also has a strong interest in security governance, being a qualified ISO 27001 auditor.
Be the first to know about developments in secure information exchange