Support
No items found.

Australia Partners with International Cyber Agencies to Publish “Principles of Operational Technology Cybersecurity”

October 10, 2024

The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has just published “Principles of Operational Technology Cybersecurity.” This is actually a global effort, with ASD’s ACSC collaborating with all of the following organizations on this OT security guide:

  • U.S. Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI), Multi-State Information Sharing and AnalysisCenter (MS-ISAC)
  • United Kingdom’s National Cyber Security Centre (NCSC-UK)
  • Canadian Centre for Cyber Security (CyberCentre)
  • New Zealand’s National Cyber Security Centre (NCSC-NZ)
  • Germany’s Federal Office for InformationSecurity (BSI Germany)
  • The Netherlands’ National Cyber Security Centre (NCSC-NL)
  • Japan’s National Center of Incident Readiness and Strategy for Cybersecurity (NISC) and National Police Agency (NPA)
  • The Republic of Korea’s National Intelligence Service (NIS) and NIS’ National Cyber Security Center (NCSC) 

The “Principles of Operational Technology Cybersecurity” guide centers around 6 key principles:

  1. Safety is paramount
  2. Knowledge of the business is crucial
  3. OT data is extremely valuable and needs to be protected
  4. Segment and segregate OT from all other networks
  5. The supply chain must be secure
  6. People are essential for OT cyber security

The objective for this guide is for each of the 6 principles to be considered when any OT decision is made. It’s sort of an evaluation checklist to ensure decisions around the design, implementation or management of OT won’t negatively impact the cybersecurity and safety of the operations. This is not technical document outlining specific security capabilities, but may be valuable for organizations looking to establish establish alignment, communication and governance across various teams and levels throughout the organizations.

You can access the full guide for free here: https://www.cyber.gov.au/about-us/view-all-content/publications/principles-operational-technology-cyber-security

CISA also lists it in their resources here: https://www.cisa.gov/resources-tools/resources/principles-operational-technology-cyber-security