Re: SCADA

[email protected] (Jim Seymour)
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
"Bertolett, Richard" <[email protected]> wrote:
> 
[snip]
> 
> Security, particularly cyber-security, is best implemented in layers.

I think of it more as "defense in depth."

> So yes, you do need an anti-virus system, and yes, you do need to apply
> MS security patches,
[snip]

Eh.  My personal experience, over the years, is that AV software is
relatively worthless as a preventive tool.  As for MS' security
patches: If you have the machines in question isolated from hostile
networks, most of them aren't strictly necessary, IMO.  Not that these
are a bad thing, mind you.  In any event: I suspect there's been a
misunderstanding...

>... it is
> much more secure to retrieve patches and virus sigs from an internal
> server, say little of the internet connection bandwidth usage.

I think there may've been some confusion induced by the way Mr. Loe
phrased things.  (Correct me if I'm wrong, Brian.)  I *believe* their
SCADA network is firewalled from the business network; the business
network is firewalled from the Internet; and there are some *few*
connections, of very specific types, allowed between specific machines
on the SCADA network and specific machines on the business network.

I *believe* what some people want is to allow the machines on the SCADA
network access to the 'net, and to allow incoming (allegedly secure)
connections from the 'net into the SCADA network.

Hmph.

I don't believe convenience should *ever* trump security.  I believe
that when convenience is allowed to trump security, you get what we
have today: Wide-spread compromising of networks.

[remainder snipped]

Regards,
Jim
-- 
Note: My mail server employs *very* aggressive anti-spam
filtering.  If you reply to this email and your email is
rejected, please accept my apologies and let me know via my
web form at <http://jimsun.linxnet.com/contact/scform.php>.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.