Risk Manager System Deployment Assurance for Industrial Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems face increasing cyber-security concerns due to unaddressed vulnerabilities in networked devices from various vendors, making it difficult to quickly determine potential risks and ensure monitoring does not disrupt operations or safety.
Innovation Solution
A risk manager system identifies vulnerable devices, evaluates system resource usage, and provides recommendations on whether to proceed with monitoring, ensuring that monitoring does not jeopardize system safety or production by checking for hardware, software, and security prerequisites.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If monitoring is implemented on vulnerable devices, then security risks are detected, but system safety and production may be jeopardized due to resource constraints
Solution Approach 1:
The system performs preliminary deployment assurance checks before monitoring is activated. These checks evaluate resource usage, hardware capabilities, software prerequisites, and security configurations in advance to ensure that monitoring will not compromise system safety or production while still detecting security risks.
Solution Approach 2:
The system introduces an intermediary assessment layer between the monitoring function and the industrial control system. This intermediary evaluates multiple factors (resource usage, hardware, software, security) and provides a risk score that determines whether monitoring should proceed, thus mediating between security detection needs and system safety concerns.
2Reliability
If comprehensive monitoring is deployed across all vulnerable devices, then security coverage is improved, but system complexity and resource requirements increase
Solution Approach 1:
The system applies different monitoring approaches and assessment criteria to different devices based on their specific characteristics. Instead of a uniform monitoring deployment, each device is evaluated individually for resource usage, hardware capabilities, software prerequisites, and security configurations, allowing tailored monitoring strategies that reduce overall system complexity.
Solution Approach 2:
The system changes multiple parameters simultaneously including resource usage thresholds, hardware requirements, software version prerequisites, and security configuration settings. By adjusting these parameters based on device-specific conditions, the system achieves comprehensive security coverage without uniformly increasing complexity across all devices.
3Reliability
If monitoring resources are allocated to vulnerable devices, then security detection capability is enhanced, but available system resources are consumed
Solution Approach 1:
The system performs a limited set of critical checks (resource usage, hardware, software, security) rather than exhaustive monitoring of all possible parameters. This partial action approach provides sufficient security detection capability while consuming minimal system resources, avoiding the need to monitor every aspect of each device.
Solution Approach 2:
The deployment assurance checks are designed to evaluate and manage their own resource requirements. By assessing resource usage as part of the deployment process, the system ensures that security detection activities are self-regulating and do not excessively consume system resources that could impact safety or production.
Data Source
AI summary
This disclosure provides an apparatus and method for deployment assurance checks for monitoring industrial control systems and other systems. A method includes identifying, by a risk manager system, a plurality of connected devices that are vulnerable to cyber-security risks. The method includes determining devices to be monitored from the plurality of connected devices. The method includes evaluating system resource usage, by the risk manager system, on each device to be monitored. The method includes providing recommendations to a user as to whether or not the user should proceed with the monitoring, based on the evaluation.


