SlideShare uma empresa Scribd logo
1 de 16
1
Question Functional Area Description
Do I have a building
control system
cybersecurity
program
(governance,
policies, roles &
responsibilities)?
Security Program
(Governance,
Policy, Roles)
Ensure that the security program has
support and sponsorship from senior
leadership.
Ensure that the security program includes
governance, policy, and role descriptions
for both OT and IT.
2
Question Functional Area Description
Are all the devices and
software that run my
building(s) accounted
for in an up-to-date
asset inventory
program?
System Asset
Inventory (Hardware
and Software)
A system asset inventory must be actively
managed to keep information up to date. This
applies to both hardware and software for all
components in the system. The information
included should be at a minimum of the following:
 Manufacturer
 Model name
 Model number
 Manufacturer support status (End of
Life)
 Operating system (OS)/firmware
manufacturer/version
 List of applications
manufacturer/version
 Location (building, floor, room
number)
 Network Address (e.g. IP)
3
Question Functional Area Description
Have I identified
critical building
systems and
performed risk
assessments?
Risk Assessment
with Identification
of Essential
Functions
Documentation that shows how, when, and
what was assessed. The risk assessment
results must also include a risk rating that
identifies critical systems and/or devices that
would affect the operations of the building.
4
Question Functional Area Description
Do I have a complete,
up-to-date list of
each service provider
that supports the
systems within my
buildings?
Service Provider
Management
Provide a list of service providers. With the
following information:
 Service provider name
 Service provider security contact
 Service scope
 Service provider’s responsibilities
 Service provider agreements
 List of authorized service provider
personnel
5
Question Functional Area Description
Who controls access
to my building
control networks
locally and remotely?
System/Network
Access Control
(remote and local)
Documents that outline how, who, and when
anyone connects to the BACS system and/or
network.
 Account names
 Account policies
 Roles
 Permissions
 Access methods (local/remote)
6
Question Functional Area Description
Are all building
control networks
documented?
Physical and
Logical Network
Architecture
Drawing
Actively managed drawings that include:
 How the networks are interconnected
 Description of systems and services on
the network
 Description of systems and services that
connect to the network
 Network management (devices,
software, and services)
7
Question Functional Area Description
Are all building
control systems,
including the devices
throughout the
building, accurately
and consistently
backed up?
System
Backup/Restore
BACS backup documentation identifies:
 Scope (what is being backed up)
 Frequency
 Method
 Storage (online/offline)
 Location (onsite/offsite)
8
Question Functional Area Description
Do I control physical
access to building
systems in my
facility?
Physical Access
Control
Documented physical access control
establishes guidelines for asset owner-
employees and service providers. At a
minimum, these guidelines identify:
 Who has access to what location/area
 Access methods (key checkout, card,
biometric, etc.)
 Enrollment Process
 Restrictions
9
Question Functional Area Description
Do I control access to
accounts used to
login to building
systems in my
facility?
System Account
Management
Processes for identifying users, adding and
removing accounts, assigning permissions,
and periodic review of accounts and
permissions. Include any additional policies
and procedures for privileged accounts
(e.g., administrator accounts)
10
Question Functional Area Description
Do you know how all
building systems
networks are
connected to each
other?
Network
Infrastructure
Management
Documented network infrastructure
management deals with the oversight of key
OT infrastructure elements that are required
to deliver building control and monitoring.
These can include networking components,
but the primary focus of network
infrastructure management also includes
physical components such as networking.
11
Question Functional Area Description
Do you have change
management for
building systems with
the appropriate level
of approval?
Change
Management
Documentation that describes the practices
designed to ensure successful prioritizing,
approval, scheduling, and execution of
changes to a BACS.
11
12
Question Functional Area Description
Is your As-built
documentation for
your building systems
kept up to date?
Updated As-builts
System
Documentation
As-built system documentation must reflect
the system as it is configured currently.
12
13
Question Functional Area Description
Do you periodically
verify that your
security measures are
configured correctly
and operational?
System Security
Verification
This documentation shows that the systems
have been commissioned/reviewed to
ensure that cybersecurity measures have
been implemented. This documentation
must also show ongoing reviews to ensure
that the implemented cybersecurity
measures have not been altered or removed.
13
14
Question Functional Area Description
Do you have an
incident response
and recovery plan for
your building systems
that include
cybersecurity
incidents, and do you
periodically test it?
Incident Response
and Recovery
Incident response or what happens when an
event occurs documentation must include:
 Roles & responsibilities
 Communication plan
 Incident prevention
 Monitoring
 Containment of an event
 Remediation processes
 Recovery & restoration processes
 Post-event analysis & forensics processes
14
15
Question Functional Area Description
Do you have building
system security
awareness and
training programs
that are appropriate
for each role?
Security
Awareness and
Skills Training
Security awareness and training
documentation must show:
 Areas of focus
 Expectations
 Frequency
 Active management to stay current on
cybersecurity trends
15
16
Question Functional Area Description
Do you have a
comprehensive
approach to
protecting data at
rest or in motion?
Data Protection Data protection policy and procedure
documentation that includes:
 Data classification
 Data protection (at rest or in motion)
 Data retention
 Data purging
16

Mais conteúdo relacionado

Semelhante a ARE YOU READY FOR A CYBER EVENT - ASK YOURSELF THESE QUESTIONS.pptx

Cst 610 Your world/newtonhelp.com
Cst 610 Your world/newtonhelp.comCst 610 Your world/newtonhelp.com
Cst 610 Your world/newtonhelp.comamaranthbeg93
 
Cst 610 Education is Power/newtonhelp.com
Cst 610 Education is Power/newtonhelp.comCst 610 Education is Power/newtonhelp.com
Cst 610 Education is Power/newtonhelp.comamaranthbeg73
 
Cst 610 Motivated Minds/newtonhelp.com
Cst 610 Motivated Minds/newtonhelp.comCst 610 Motivated Minds/newtonhelp.com
Cst 610 Motivated Minds/newtonhelp.comamaranthbeg53
 
Supplier security assessment questionnaire
Supplier security assessment questionnaireSupplier security assessment questionnaire
Supplier security assessment questionnairePriyanka Aash
 
Cyb 610 Inspiring Innovation--tutorialrank.com
Cyb 610 Inspiring Innovation--tutorialrank.comCyb 610 Inspiring Innovation--tutorialrank.com
Cyb 610 Inspiring Innovation--tutorialrank.comPrescottLunt386
 
Software Architecture and Design Introduction
Software Architecture and Design IntroductionSoftware Architecture and Design Introduction
Software Architecture and Design IntroductionUsman Khan
 
Ch5 software imprementation1.0
Ch5 software imprementation1.0Ch5 software imprementation1.0
Ch5 software imprementation1.0Kittitouch Suteeca
 
Software Architecture Standard IEEE 1471
Software Architecture Standard IEEE 1471Software Architecture Standard IEEE 1471
Software Architecture Standard IEEE 1471vconovalov
 
Ch 2-RE-process.pptx
Ch 2-RE-process.pptxCh 2-RE-process.pptx
Ch 2-RE-process.pptxbalewayalew
 
Ch 9 traceability and verification
Ch 9 traceability and verificationCh 9 traceability and verification
Ch 9 traceability and verificationKittitouch Suteeca
 
Database Security Assessment Transcript You are a contracting office.docx
Database Security Assessment Transcript You are a contracting office.docxDatabase Security Assessment Transcript You are a contracting office.docx
Database Security Assessment Transcript You are a contracting office.docxwhittemorelucilla
 
Testing Types And Models
Testing Types And ModelsTesting Types And Models
Testing Types And Modelsnazeer pasha
 
Robert donald resume iam 1
Robert donald resume iam 1Robert donald resume iam 1
Robert donald resume iam 1Robert Donald
 
Aspect Oriented Programming - AOP/AOSD
Aspect Oriented Programming - AOP/AOSDAspect Oriented Programming - AOP/AOSD
Aspect Oriented Programming - AOP/AOSDCan R. PAHALI
 
Computer system validation
Computer system validation Computer system validation
Computer system validation ShameerAbid
 
Requirement Engineering for Dependable Systems
Requirement Engineering for Dependable SystemsRequirement Engineering for Dependable Systems
Requirement Engineering for Dependable SystemsKamalika Guha Roy
 
System Development Life_IntroductionCycle.pdf
System Development Life_IntroductionCycle.pdfSystem Development Life_IntroductionCycle.pdf
System Development Life_IntroductionCycle.pdfpncitechnologies
 

Semelhante a ARE YOU READY FOR A CYBER EVENT - ASK YOURSELF THESE QUESTIONS.pptx (20)

Cst 610 Your world/newtonhelp.com
Cst 610 Your world/newtonhelp.comCst 610 Your world/newtonhelp.com
Cst 610 Your world/newtonhelp.com
 
Cst 610 Education is Power/newtonhelp.com
Cst 610 Education is Power/newtonhelp.comCst 610 Education is Power/newtonhelp.com
Cst 610 Education is Power/newtonhelp.com
 
Cst 610 Motivated Minds/newtonhelp.com
Cst 610 Motivated Minds/newtonhelp.comCst 610 Motivated Minds/newtonhelp.com
Cst 610 Motivated Minds/newtonhelp.com
 
Charles M Cottrell
Charles M CottrellCharles M Cottrell
Charles M Cottrell
 
System testing
System testingSystem testing
System testing
 
Supplier security assessment questionnaire
Supplier security assessment questionnaireSupplier security assessment questionnaire
Supplier security assessment questionnaire
 
Cyb 610 Inspiring Innovation--tutorialrank.com
Cyb 610 Inspiring Innovation--tutorialrank.comCyb 610 Inspiring Innovation--tutorialrank.com
Cyb 610 Inspiring Innovation--tutorialrank.com
 
Software Architecture and Design Introduction
Software Architecture and Design IntroductionSoftware Architecture and Design Introduction
Software Architecture and Design Introduction
 
Sdlc1
Sdlc1Sdlc1
Sdlc1
 
Ch5 software imprementation1.0
Ch5 software imprementation1.0Ch5 software imprementation1.0
Ch5 software imprementation1.0
 
Software Architecture Standard IEEE 1471
Software Architecture Standard IEEE 1471Software Architecture Standard IEEE 1471
Software Architecture Standard IEEE 1471
 
Ch 2-RE-process.pptx
Ch 2-RE-process.pptxCh 2-RE-process.pptx
Ch 2-RE-process.pptx
 
Ch 9 traceability and verification
Ch 9 traceability and verificationCh 9 traceability and verification
Ch 9 traceability and verification
 
Database Security Assessment Transcript You are a contracting office.docx
Database Security Assessment Transcript You are a contracting office.docxDatabase Security Assessment Transcript You are a contracting office.docx
Database Security Assessment Transcript You are a contracting office.docx
 
Testing Types And Models
Testing Types And ModelsTesting Types And Models
Testing Types And Models
 
Robert donald resume iam 1
Robert donald resume iam 1Robert donald resume iam 1
Robert donald resume iam 1
 
Aspect Oriented Programming - AOP/AOSD
Aspect Oriented Programming - AOP/AOSDAspect Oriented Programming - AOP/AOSD
Aspect Oriented Programming - AOP/AOSD
 
Computer system validation
Computer system validation Computer system validation
Computer system validation
 
Requirement Engineering for Dependable Systems
Requirement Engineering for Dependable SystemsRequirement Engineering for Dependable Systems
Requirement Engineering for Dependable Systems
 
System Development Life_IntroductionCycle.pdf
System Development Life_IntroductionCycle.pdfSystem Development Life_IntroductionCycle.pdf
System Development Life_IntroductionCycle.pdf
 

Último

2k Shot Call girls Karol Bagh Delhi 9205541914
2k Shot Call girls Karol Bagh Delhi 92055419142k Shot Call girls Karol Bagh Delhi 9205541914
2k Shot Call girls Karol Bagh Delhi 9205541914Delhi Call girls
 
9990771857 Call Girls in Dwarka Sector 6 Delhi (Call Girls) Delhi
9990771857 Call Girls in Dwarka Sector 6 Delhi (Call Girls) Delhi9990771857 Call Girls in Dwarka Sector 6 Delhi (Call Girls) Delhi
9990771857 Call Girls in Dwarka Sector 6 Delhi (Call Girls) Delhidelhimodel235
 
Best Deal Virtual Space in Satya The Hive Tata Zudio 750 Sqft 1.89 Cr All inc...
Best Deal Virtual Space in Satya The Hive Tata Zudio 750 Sqft 1.89 Cr All inc...Best Deal Virtual Space in Satya The Hive Tata Zudio 750 Sqft 1.89 Cr All inc...
Best Deal Virtual Space in Satya The Hive Tata Zudio 750 Sqft 1.89 Cr All inc...ApartmentWala1
 
TENANT SCREENING REPORT SERVICES​ How Tenant Screening Reports Work
TENANT SCREENING REPORT SERVICES​ How Tenant Screening Reports WorkTENANT SCREENING REPORT SERVICES​ How Tenant Screening Reports Work
TENANT SCREENING REPORT SERVICES​ How Tenant Screening Reports WorkTurbo Tenant
 
call girls in ganesh nagar Delhi 8264348440 ✅ call girls ❤️
call girls in ganesh nagar Delhi 8264348440 ✅ call girls ❤️call girls in ganesh nagar Delhi 8264348440 ✅ call girls ❤️
call girls in ganesh nagar Delhi 8264348440 ✅ call girls ❤️soniya singh
 
Call Girls in shastri nagar Delhi 8264348440 ✅ call girls ❤️
Call Girls in shastri nagar Delhi 8264348440 ✅ call girls ❤️Call Girls in shastri nagar Delhi 8264348440 ✅ call girls ❤️
Call Girls in shastri nagar Delhi 8264348440 ✅ call girls ❤️soniya singh
 
9990771857 Call Girls Dwarka Sector 9 Delhi (Call Girls ) Delhi
9990771857 Call Girls Dwarka Sector 9 Delhi (Call Girls ) Delhi9990771857 Call Girls Dwarka Sector 9 Delhi (Call Girls ) Delhi
9990771857 Call Girls Dwarka Sector 9 Delhi (Call Girls ) Delhidelhimodel235
 
Magarpatta Nova Elegance Mundhwa Pune E-Brochure.pdf
Magarpatta Nova Elegance Mundhwa Pune  E-Brochure.pdfMagarpatta Nova Elegance Mundhwa Pune  E-Brochure.pdf
Magarpatta Nova Elegance Mundhwa Pune E-Brochure.pdfManishSaxena95
 
SVN Live 5.6.24 Weekly Property Broadcast
SVN Live 5.6.24 Weekly Property BroadcastSVN Live 5.6.24 Weekly Property Broadcast
SVN Live 5.6.24 Weekly Property BroadcastSVN International Corp.
 
9990771857 Call Girls in Dwarka Sector 7 Delhi (Call Girls) Delhi
9990771857 Call Girls in Dwarka Sector 7 Delhi (Call Girls) Delhi9990771857 Call Girls in Dwarka Sector 7 Delhi (Call Girls) Delhi
9990771857 Call Girls in Dwarka Sector 7 Delhi (Call Girls) Delhidelhimodel235
 
3D Architectural Rendering Company by Panoram CGI
3D Architectural Rendering Company by Panoram CGI3D Architectural Rendering Company by Panoram CGI
3D Architectural Rendering Company by Panoram CGIPanoram CGI
 
Girls in Kalyanpuri }Delhi↫8447779280↬Escort Service. In Delhi NCR
Girls in Kalyanpuri }Delhi↫8447779280↬Escort Service. In Delhi NCRGirls in Kalyanpuri }Delhi↫8447779280↬Escort Service. In Delhi NCR
Girls in Kalyanpuri }Delhi↫8447779280↬Escort Service. In Delhi NCRasmaqueen5
 
Premium Villa Projects in Sarjapur Road Bengaluru
Premium Villa Projects in Sarjapur Road BengaluruPremium Villa Projects in Sarjapur Road Bengaluru
Premium Villa Projects in Sarjapur Road BengaluruShivaSeo3
 
Maha Mauka Squarefeet Brochure |Maha Mauka Squarefeet PDF Brochure|
Maha Mauka Squarefeet Brochure |Maha Mauka Squarefeet PDF Brochure|Maha Mauka Squarefeet Brochure |Maha Mauka Squarefeet PDF Brochure|
Maha Mauka Squarefeet Brochure |Maha Mauka Squarefeet PDF Brochure|AkshayJoshi575980
 
Call Girls In Mayur Vihar Delhi ☆↫8447779280 ❤Escorts Service In Delhi
Call Girls In Mayur Vihar Delhi ☆↫8447779280 ❤Escorts Service In DelhiCall Girls In Mayur Vihar Delhi ☆↫8447779280 ❤Escorts Service In Delhi
Call Girls In Mayur Vihar Delhi ☆↫8447779280 ❤Escorts Service In Delhiasmaqueen5
 
BDSM⚡Call Girls in Sector 57 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 57 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 57 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 57 Noida Escorts >༒8448380779 Escort ServiceDelhi Call girls
 
Call Girls In Laxmi Nagar Delhi +91-8447779280! !Best Woman Seeking Man Escor...
Call Girls In Laxmi Nagar Delhi +91-8447779280! !Best Woman Seeking Man Escor...Call Girls In Laxmi Nagar Delhi +91-8447779280! !Best Woman Seeking Man Escor...
Call Girls In Laxmi Nagar Delhi +91-8447779280! !Best Woman Seeking Man Escor...asmaqueen5
 
Call Girls In Vasant Vihar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Vasant Vihar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Vasant Vihar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Vasant Vihar Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Kolte Patil Kharadi Pune E Brochure.pdf
Kolte Patil Kharadi Pune E  Brochure.pdfKolte Patil Kharadi Pune E  Brochure.pdf
Kolte Patil Kharadi Pune E Brochure.pdfabbu831446
 
Kohinoor Flats In Hinjewadi Phase 2 | Homes Built To Suit Your Needs
Kohinoor Flats In Hinjewadi Phase 2 | Homes Built To Suit Your NeedsKohinoor Flats In Hinjewadi Phase 2 | Homes Built To Suit Your Needs
Kohinoor Flats In Hinjewadi Phase 2 | Homes Built To Suit Your Needsaidasheikh47
 

Último (20)

2k Shot Call girls Karol Bagh Delhi 9205541914
2k Shot Call girls Karol Bagh Delhi 92055419142k Shot Call girls Karol Bagh Delhi 9205541914
2k Shot Call girls Karol Bagh Delhi 9205541914
 
9990771857 Call Girls in Dwarka Sector 6 Delhi (Call Girls) Delhi
9990771857 Call Girls in Dwarka Sector 6 Delhi (Call Girls) Delhi9990771857 Call Girls in Dwarka Sector 6 Delhi (Call Girls) Delhi
9990771857 Call Girls in Dwarka Sector 6 Delhi (Call Girls) Delhi
 
Best Deal Virtual Space in Satya The Hive Tata Zudio 750 Sqft 1.89 Cr All inc...
Best Deal Virtual Space in Satya The Hive Tata Zudio 750 Sqft 1.89 Cr All inc...Best Deal Virtual Space in Satya The Hive Tata Zudio 750 Sqft 1.89 Cr All inc...
Best Deal Virtual Space in Satya The Hive Tata Zudio 750 Sqft 1.89 Cr All inc...
 
TENANT SCREENING REPORT SERVICES​ How Tenant Screening Reports Work
TENANT SCREENING REPORT SERVICES​ How Tenant Screening Reports WorkTENANT SCREENING REPORT SERVICES​ How Tenant Screening Reports Work
TENANT SCREENING REPORT SERVICES​ How Tenant Screening Reports Work
 
call girls in ganesh nagar Delhi 8264348440 ✅ call girls ❤️
call girls in ganesh nagar Delhi 8264348440 ✅ call girls ❤️call girls in ganesh nagar Delhi 8264348440 ✅ call girls ❤️
call girls in ganesh nagar Delhi 8264348440 ✅ call girls ❤️
 
Call Girls in shastri nagar Delhi 8264348440 ✅ call girls ❤️
Call Girls in shastri nagar Delhi 8264348440 ✅ call girls ❤️Call Girls in shastri nagar Delhi 8264348440 ✅ call girls ❤️
Call Girls in shastri nagar Delhi 8264348440 ✅ call girls ❤️
 
9990771857 Call Girls Dwarka Sector 9 Delhi (Call Girls ) Delhi
9990771857 Call Girls Dwarka Sector 9 Delhi (Call Girls ) Delhi9990771857 Call Girls Dwarka Sector 9 Delhi (Call Girls ) Delhi
9990771857 Call Girls Dwarka Sector 9 Delhi (Call Girls ) Delhi
 
Magarpatta Nova Elegance Mundhwa Pune E-Brochure.pdf
Magarpatta Nova Elegance Mundhwa Pune  E-Brochure.pdfMagarpatta Nova Elegance Mundhwa Pune  E-Brochure.pdf
Magarpatta Nova Elegance Mundhwa Pune E-Brochure.pdf
 
SVN Live 5.6.24 Weekly Property Broadcast
SVN Live 5.6.24 Weekly Property BroadcastSVN Live 5.6.24 Weekly Property Broadcast
SVN Live 5.6.24 Weekly Property Broadcast
 
9990771857 Call Girls in Dwarka Sector 7 Delhi (Call Girls) Delhi
9990771857 Call Girls in Dwarka Sector 7 Delhi (Call Girls) Delhi9990771857 Call Girls in Dwarka Sector 7 Delhi (Call Girls) Delhi
9990771857 Call Girls in Dwarka Sector 7 Delhi (Call Girls) Delhi
 
3D Architectural Rendering Company by Panoram CGI
3D Architectural Rendering Company by Panoram CGI3D Architectural Rendering Company by Panoram CGI
3D Architectural Rendering Company by Panoram CGI
 
Girls in Kalyanpuri }Delhi↫8447779280↬Escort Service. In Delhi NCR
Girls in Kalyanpuri }Delhi↫8447779280↬Escort Service. In Delhi NCRGirls in Kalyanpuri }Delhi↫8447779280↬Escort Service. In Delhi NCR
Girls in Kalyanpuri }Delhi↫8447779280↬Escort Service. In Delhi NCR
 
Premium Villa Projects in Sarjapur Road Bengaluru
Premium Villa Projects in Sarjapur Road BengaluruPremium Villa Projects in Sarjapur Road Bengaluru
Premium Villa Projects in Sarjapur Road Bengaluru
 
Maha Mauka Squarefeet Brochure |Maha Mauka Squarefeet PDF Brochure|
Maha Mauka Squarefeet Brochure |Maha Mauka Squarefeet PDF Brochure|Maha Mauka Squarefeet Brochure |Maha Mauka Squarefeet PDF Brochure|
Maha Mauka Squarefeet Brochure |Maha Mauka Squarefeet PDF Brochure|
 
Call Girls In Mayur Vihar Delhi ☆↫8447779280 ❤Escorts Service In Delhi
Call Girls In Mayur Vihar Delhi ☆↫8447779280 ❤Escorts Service In DelhiCall Girls In Mayur Vihar Delhi ☆↫8447779280 ❤Escorts Service In Delhi
Call Girls In Mayur Vihar Delhi ☆↫8447779280 ❤Escorts Service In Delhi
 
BDSM⚡Call Girls in Sector 57 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 57 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 57 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 57 Noida Escorts >༒8448380779 Escort Service
 
Call Girls In Laxmi Nagar Delhi +91-8447779280! !Best Woman Seeking Man Escor...
Call Girls In Laxmi Nagar Delhi +91-8447779280! !Best Woman Seeking Man Escor...Call Girls In Laxmi Nagar Delhi +91-8447779280! !Best Woman Seeking Man Escor...
Call Girls In Laxmi Nagar Delhi +91-8447779280! !Best Woman Seeking Man Escor...
 
Call Girls In Vasant Vihar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Vasant Vihar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Vasant Vihar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Vasant Vihar Delhi 💯Call Us 🔝8264348440🔝
 
Kolte Patil Kharadi Pune E Brochure.pdf
Kolte Patil Kharadi Pune E  Brochure.pdfKolte Patil Kharadi Pune E  Brochure.pdf
Kolte Patil Kharadi Pune E Brochure.pdf
 
Kohinoor Flats In Hinjewadi Phase 2 | Homes Built To Suit Your Needs
Kohinoor Flats In Hinjewadi Phase 2 | Homes Built To Suit Your NeedsKohinoor Flats In Hinjewadi Phase 2 | Homes Built To Suit Your Needs
Kohinoor Flats In Hinjewadi Phase 2 | Homes Built To Suit Your Needs
 

ARE YOU READY FOR A CYBER EVENT - ASK YOURSELF THESE QUESTIONS.pptx

  • 1. 1 Question Functional Area Description Do I have a building control system cybersecurity program (governance, policies, roles & responsibilities)? Security Program (Governance, Policy, Roles) Ensure that the security program has support and sponsorship from senior leadership. Ensure that the security program includes governance, policy, and role descriptions for both OT and IT.
  • 2. 2 Question Functional Area Description Are all the devices and software that run my building(s) accounted for in an up-to-date asset inventory program? System Asset Inventory (Hardware and Software) A system asset inventory must be actively managed to keep information up to date. This applies to both hardware and software for all components in the system. The information included should be at a minimum of the following:  Manufacturer  Model name  Model number  Manufacturer support status (End of Life)  Operating system (OS)/firmware manufacturer/version  List of applications manufacturer/version  Location (building, floor, room number)  Network Address (e.g. IP)
  • 3. 3 Question Functional Area Description Have I identified critical building systems and performed risk assessments? Risk Assessment with Identification of Essential Functions Documentation that shows how, when, and what was assessed. The risk assessment results must also include a risk rating that identifies critical systems and/or devices that would affect the operations of the building.
  • 4. 4 Question Functional Area Description Do I have a complete, up-to-date list of each service provider that supports the systems within my buildings? Service Provider Management Provide a list of service providers. With the following information:  Service provider name  Service provider security contact  Service scope  Service provider’s responsibilities  Service provider agreements  List of authorized service provider personnel
  • 5. 5 Question Functional Area Description Who controls access to my building control networks locally and remotely? System/Network Access Control (remote and local) Documents that outline how, who, and when anyone connects to the BACS system and/or network.  Account names  Account policies  Roles  Permissions  Access methods (local/remote)
  • 6. 6 Question Functional Area Description Are all building control networks documented? Physical and Logical Network Architecture Drawing Actively managed drawings that include:  How the networks are interconnected  Description of systems and services on the network  Description of systems and services that connect to the network  Network management (devices, software, and services)
  • 7. 7 Question Functional Area Description Are all building control systems, including the devices throughout the building, accurately and consistently backed up? System Backup/Restore BACS backup documentation identifies:  Scope (what is being backed up)  Frequency  Method  Storage (online/offline)  Location (onsite/offsite)
  • 8. 8 Question Functional Area Description Do I control physical access to building systems in my facility? Physical Access Control Documented physical access control establishes guidelines for asset owner- employees and service providers. At a minimum, these guidelines identify:  Who has access to what location/area  Access methods (key checkout, card, biometric, etc.)  Enrollment Process  Restrictions
  • 9. 9 Question Functional Area Description Do I control access to accounts used to login to building systems in my facility? System Account Management Processes for identifying users, adding and removing accounts, assigning permissions, and periodic review of accounts and permissions. Include any additional policies and procedures for privileged accounts (e.g., administrator accounts)
  • 10. 10 Question Functional Area Description Do you know how all building systems networks are connected to each other? Network Infrastructure Management Documented network infrastructure management deals with the oversight of key OT infrastructure elements that are required to deliver building control and monitoring. These can include networking components, but the primary focus of network infrastructure management also includes physical components such as networking.
  • 11. 11 Question Functional Area Description Do you have change management for building systems with the appropriate level of approval? Change Management Documentation that describes the practices designed to ensure successful prioritizing, approval, scheduling, and execution of changes to a BACS. 11
  • 12. 12 Question Functional Area Description Is your As-built documentation for your building systems kept up to date? Updated As-builts System Documentation As-built system documentation must reflect the system as it is configured currently. 12
  • 13. 13 Question Functional Area Description Do you periodically verify that your security measures are configured correctly and operational? System Security Verification This documentation shows that the systems have been commissioned/reviewed to ensure that cybersecurity measures have been implemented. This documentation must also show ongoing reviews to ensure that the implemented cybersecurity measures have not been altered or removed. 13
  • 14. 14 Question Functional Area Description Do you have an incident response and recovery plan for your building systems that include cybersecurity incidents, and do you periodically test it? Incident Response and Recovery Incident response or what happens when an event occurs documentation must include:  Roles & responsibilities  Communication plan  Incident prevention  Monitoring  Containment of an event  Remediation processes  Recovery & restoration processes  Post-event analysis & forensics processes 14
  • 15. 15 Question Functional Area Description Do you have building system security awareness and training programs that are appropriate for each role? Security Awareness and Skills Training Security awareness and training documentation must show:  Areas of focus  Expectations  Frequency  Active management to stay current on cybersecurity trends 15
  • 16. 16 Question Functional Area Description Do you have a comprehensive approach to protecting data at rest or in motion? Data Protection Data protection policy and procedure documentation that includes:  Data classification  Data protection (at rest or in motion)  Data retention  Data purging 16