The shop floor · 2.1
Machines older than the requirements
A control written for a server, applied to a lathe with a shared login, a decade-old operating system and a USB port.
For a related human-factors concept, task switching cost provides additional context for interpreting behaviour without jumping to conclusions.
For an independent reference point, see SANS industrial control systems resources.
The premise
A control written for a server, applied to a lathe
The security requirements assume a system with individual identities, centralised logging, patching and access control. A computer numerical control machine on a shop floor commonly has none of those.
It may run an operating system out of support for a decade. It may have one login shared by three shifts. It may accept a program from a USB stick because that is how programs have always reached it. And it may be under a maintenance contract that voids if anything is changed.
None of that is negligence. It is a capital asset with a working life measured in decades meeting a requirement written for equipment with a working life measured in years.
The routes
How files actually reach a machine
Ask, and then watch, because the answers differ.
- A network share that everybody can reach.
- A USB stick carried from the programming office.
- Email to a shared mailbox, printed or transferred by hand.
- A vendor's remote support connection, opened when needed and sometimes left open.
- A personal device, because the official route was slow.
The last one is the one that never appears on a network diagram and frequently carries the most sensitive file in the building.
The options
Four ways to treat a machine that cannot be secured
Segment it. Put it behind a boundary that can enforce what the machine cannot. Common, effective, and it moves the control rather than removing the need for it.
Broker the transfer. Nothing reaches the machine except through a checked, logged intermediary. This is where governance of the file, rather than of the network, does the work.
Replace the controller. Expensive and sometimes the answer, particularly where the machine is otherwise sound.
Take it out of scope. If it never touches covered information, say so, document why, and hold the line.
Evidence
What an assessor will ask about the floor
Which machines handle covered information. How a program gets to each. Who authorised the last transfer. What log shows it. And what would happen if somebody put an unauthorised file on a machine tomorrow.
The last question is the one that separates a written policy from a working control, and it is answerable only if something is watching.
The media protection and system and communications protection families of the NIST publication, which set out the requirements these questions test.
The questions are ours; the requirements behind them are published and can be read directly.
The removable media problem
Banning USB rarely survives contact with production
A prohibition that stops a job running gets worked around by the person under pressure to ship, and the workaround is invisible.
What works better is a controlled path that is faster than the workaround: an authorised transfer that takes a minute, logs itself, and does not require finding somebody. Where the compliant route is the convenient route, the policy holds without enforcement.
Where it is not, the policy is a document rather than a control, and an assessor will find that out by asking an operator rather than by reading it.
Where to start
An inventory nobody has
A list of machines, what each handles, how files reach it, and who can touch it. Most manufacturers do not have this and every assessment requires it.
It takes a walk round the floor with a notebook and a week of follow-up, it is the cheapest thing in this part, and it usually surprises the person who commissioned it.
The maintenance contract
The clause that blocks the obvious fix
Many machine tools are supported under agreements that void if the controller is modified, patched or connected differently. That is a commercial constraint rather than a technical one and it is real.
Where it applies, the four options in this entry reduce to the first two: put something in front of the machine, or control what reaches it. Both leave the machine untouched, which is why they are the ones that survive a conversation with the equipment vendor.
Shift patterns
Shared logins exist for a reason
Three shifts, one machine, a login that takes forty seconds and a job that has to start. The shared account is not laziness; it is the only arrangement that works given the interface.
Any control that adds friction at that moment will be defeated, and the defeat will not be recorded. What works is identifying the person somewhere the machine is not: at the point the file is authorised and released rather than at the point it is loaded.
Who owns this
The person who walks the floor
Compliance is usually held by somebody in quality, operations or finance, alongside another job. The information they need is on the floor, and the floor does not read policy documents.
The single most effective thing that person can do is spend a day walking round asking how files actually arrive, without judgement. The answers are freely given when nobody is being blamed, and they are usually different from what the network diagram says.
The order of work
Inventory, then routes, then controls
Know which machines handle covered information. Know how a file reaches each one, including the routes nobody authorised. Only then decide what to control, because a control placed before that knowledge protects the route you knew about and misses the one people use.
What to ask a vendor
Three questions about the floor
How does your product know what reached this machine, given that the machine cannot tell you? What does it record, and can an assessor read that record without your help? And what happens on the day the network link to it is down and a job has to run?
The third is the one that separates a product designed for a factory from one designed for an office.
Also
Elsewhere in the shop floor
- What the three levels are, and which appliesThe level is set by your contract, not by your size. Most suppliers handling controlled unclassified information are at the second.
- Reading the clause that binds youReading the clause that binds you. What the requirement says, what it means in practice, and what an assessor will ask.
- Which systems are in scopeWhich systems are in scope. What the requirement says, what it means in practice, and what an assessor will ask.
- Self-assessment, and why the scores driftedSelf-assessment, and why the scores drifted. What the requirement says, what it means in practice, and what an assessor will ask.
- Who assesses you, and how each kind worksWho assesses you, and how each kind works. What the requirement says, what it means in practice, and what an assessor will ask.
- What the standard does not requireWhat the standard does not require. What the requirement says, what it means in practice, and what an assessor will ask.
- Drawings, job packets and paperDrawings, job packets and paper. What the requirement says, what it means in practice, and what an assessor will ask.
- Removable media, and why bans failRemovable media, and why bans fail. What the requirement says, what it means in practice, and what an assessor will ask.
- Vendor remote accessVendor remote access. What the requirement says, what it means in practice, and what an assessor will ask.
- Technical data packages and what they containTechnical data packages and what they contain. What the requirement says, what it means in practice, and what an assessor will ask.
- Segmentation, and what it does not solveSegmentation, and what it does not solve. What the requirement says, what it means in practice, and what an assessor will ask.
- What insider risk actually coversWhat insider risk actually covers. What the requirement says, what it means in practice, and what an assessor will ask.
- What detection can and cannot establishWhat detection can and cannot establish. What the requirement says, what it means in practice, and what an assessor will ask.
- Monitoring, and where the law constrains itMonitoring, and where the law constrains it. What the requirement says, what it means in practice, and what an assessor will ask.
- The fortnight around a departureThe fortnight around a departure. What the requirement says, what it means in practice, and what an assessor will ask.
- Privileged access, and who reviews itPrivileged access, and who reviews it. What the requirement says, what it means in practice, and what an assessor will ask.
- False positives, and what they costFalse positives, and what they cost. What the requirement says, what it means in practice, and what an assessor will ask.
- The documents an assessor reads firstThe documents an assessor reads first. What the requirement says, what it means in practice, and what an assessor will ask.
- What counts as evidenceWhat counts as evidence. What the requirement says, what it means in practice, and what an assessor will ask.
- The findings that recurThe findings that recur. What the requirement says, what it means in practice, and what an assessor will ask.
- Plans of action, and their limitsPlans of action, and their limits. What the requirement says, what it means in practice, and what an assessor will ask.
- What the assessment week is likeWhat the assessment week is like. What the requirement says, what it means in practice, and what an assessor will ask.
- The certificate, and what it coversThe certificate, and what it covers. What the requirement says, what it means in practice, and what an assessor will ask.