Open standards security threat ignored: auditor
Wednesday, May 31st, 2006Certified information systems auditor (CISA) Barry Munns told Builder AU sister site ZDNet Australia the IT auditing profession had “largely ignored” moves by energy, gas and water utilities to adopt open standards for their telemetry and telecontrol infrastructure, often known as supervisory control and data acquisition (SCADA) systems and the dangers this created. These systems allow remote control or monitoring of infrastructure, such as substations or water pipes.
“There’s a bit of a generational change that’s happening,” Munns said.
“Moving away from fairly closed system, proprietary type structures — software and operating systems, to more open systems or public type systems. All the risks associated with things like hacking and denial of service, those risks are now very much coming to the fore in SCADA.”
Munns has audited such systems for Energy Australia, and recently joined the Australian Nuclear Science and Technology Organisation (ANSTO).
“SCADA telemetry and telecontrol systems are moving towards that open arrangement and that inter-connected kind of model,” he said.
Source and more information: builderau