The shop floor · 2.1

Machines older than the requirements

A control written for a server, applied to a lathe with a shared login, a decade-old operating system and a USB port.

For an independent reference point, see SANS industrial control systems resources.

The premise

A control written for a server, applied to a lathe

The security requirements assume a system with individual identities, centralised logging, patching and access control. A computer numerical control machine on a shop floor commonly has none of those.

It may run an operating system out of support for a decade. It may have one login shared by three shifts. It may accept a program from a USB stick because that is how programs have always reached it. And it may be under a maintenance contract that voids if anything is changed.

None of that is negligence. It is a capital asset with a working life measured in decades meeting a requirement written for equipment with a working life measured in years.

The routes

How files actually reach a machine

Ask, and then watch, because the answers differ.

  • A network share that everybody can reach.
  • A USB stick carried from the programming office.
  • Email to a shared mailbox, printed or transferred by hand.
  • A vendor's remote support connection, opened when needed and sometimes left open.
  • A personal device, because the official route was slow.

The last one is the one that never appears on a network diagram and frequently carries the most sensitive file in the building.

The options

Four ways to treat a machine that cannot be secured

Segment it. Put it behind a boundary that can enforce what the machine cannot. Common, effective, and it moves the control rather than removing the need for it.

Broker the transfer. Nothing reaches the machine except through a checked, logged intermediary. This is where governance of the file, rather than of the network, does the work.

Replace the controller. Expensive and sometimes the answer, particularly where the machine is otherwise sound.

Take it out of scope. If it never touches covered information, say so, document why, and hold the line.

Evidence

What an assessor will ask about the floor

Which machines handle covered information. How a program gets to each. Who authorised the last transfer. What log shows it. And what would happen if somebody put an unauthorised file on a machine tomorrow.

The last question is the one that separates a written policy from a working control, and it is answerable only if something is watching.

Rests on

The media protection and system and communications protection families of the NIST publication, which set out the requirements these questions test.

The questions are ours; the requirements behind them are published and can be read directly.

The removable media problem

Banning USB rarely survives contact with production

A prohibition that stops a job running gets worked around by the person under pressure to ship, and the workaround is invisible.

What works better is a controlled path that is faster than the workaround: an authorised transfer that takes a minute, logs itself, and does not require finding somebody. Where the compliant route is the convenient route, the policy holds without enforcement.

Where it is not, the policy is a document rather than a control, and an assessor will find that out by asking an operator rather than by reading it.

Where to start

An inventory nobody has

A list of machines, what each handles, how files reach it, and who can touch it. Most manufacturers do not have this and every assessment requires it.

It takes a walk round the floor with a notebook and a week of follow-up, it is the cheapest thing in this part, and it usually surprises the person who commissioned it.

The maintenance contract

The clause that blocks the obvious fix

Many machine tools are supported under agreements that void if the controller is modified, patched or connected differently. That is a commercial constraint rather than a technical one and it is real.

Where it applies, the four options in this entry reduce to the first two: put something in front of the machine, or control what reaches it. Both leave the machine untouched, which is why they are the ones that survive a conversation with the equipment vendor.

Shift patterns

Shared logins exist for a reason

Three shifts, one machine, a login that takes forty seconds and a job that has to start. The shared account is not laziness; it is the only arrangement that works given the interface.

Any control that adds friction at that moment will be defeated, and the defeat will not be recorded. What works is identifying the person somewhere the machine is not: at the point the file is authorised and released rather than at the point it is loaded.

Who owns this

The person who walks the floor

Compliance is usually held by somebody in quality, operations or finance, alongside another job. The information they need is on the floor, and the floor does not read policy documents.

The single most effective thing that person can do is spend a day walking round asking how files actually arrive, without judgement. The answers are freely given when nobody is being blamed, and they are usually different from what the network diagram says.

The order of work

Inventory, then routes, then controls

Know which machines handle covered information. Know how a file reaches each one, including the routes nobody authorised. Only then decide what to control, because a control placed before that knowledge protects the route you knew about and misses the one people use.

What to ask a vendor

Three questions about the floor

How does your product know what reached this machine, given that the machine cannot tell you? What does it record, and can an assessor read that record without your help? And what happens on the day the network link to it is down and a job has to run?

The third is the one that separates a product designed for a factory from one designed for an office.

Also

Elsewhere in the shop floor