Energy Industry
Industry: Email Alert RSS FeedAGA 12 recommends how to protect SCADA communications from cyber attack
Pipeline & Gas Journal, Nov, 2006 by William F. Rush, John A. Kinast, Aakash B. Shah
The dependence of utility infrastructure industries on unmanned facilities and Supervisory Control and Data Acquisition (SCADA) systems has created a series of high-value targets that a technologically sophisticated terrorist group or foreign government could exploit. To counter this threat, the American Gas Association (AGA) charged the AGA 12 Cryptography Working Group to develop a suite of open standards (designated AGA 12) to protect the data transmitted by SCADA systems, to authenticate the originators of messages on SCADA systems, and to ensure data integrity.
Most RecentEnergy Articles
- Why OPEC Will Have To Cut Oil Production in 2010
- How Important Are Renewables? Feinstein Blocks Desert Solar
- Copenhagen's Finale: Obama Speaks, Pessimism Abounds and a Hint of a Deal
- Wind Turbines: Not Harmful to Health, But Residents Are Up in Arms Anyway
- Stops and Starts as Copenhagen Winds Toward Its End
- More »
The fundamental goal is to make it easy for SCADA operators to specify good communication security without having to delve into complicated topics like cryptography and digital certificates. Pipelines and utilities can confidently protect their systems from cyber attack if they simply specify AGA 12 compliance for SCADA equipment and follow the recommendations in the documents. Believing that competition is the best way to assure low-cost products, AGA 12 requires that SCADA cyber security equipment can interoperate, independent of manufacturer or age.
By themselves, the AGA 12 documents protect nothing. It is only effective when manufacturers incorporate the standard into cost-effective products and utilities deploy that equipment to protect SCADA systems from potential attackers. We are pleased to see that commercial products are now available.
The AGA, the AWWA Research Foundation (AwwaRF), the Department of Energy (DOE), the Gas Technology Institute (GTI), the Technical Support Working Group (TSWG), and more than a dozen private companies combined resources to develop the AGA 12 set of recommended practices.
Initial feedback from the gas and electric industries recommended that the first AGA 12 efforts address the need for retrofit protection of serial communications for installed (legacy) SCADA systems. The reason is that such systems have lifetimes between seven and 20 years and are too expensive to be replaced for the sole purpose of incorporating security. Accordingly, the AGA 12 Working Group began development on a series of four documents, structured as follows:
* AGA Report No. 12, Part 1--"Cryptographic Protection of SCADA Communications: General Recommendations" contains the background, security policy fundamentals, and a test plan that apply generally to all areas of cryptographic protection of SCADA systems.
* AGA Report No. 12, Part2--"Cryptographic Protection of SCADA Communications: Retrofit Applications" focuses on protecting already installed, generally low-speed, serial equipment. This document contains the functional requirements and detailed technical specifications for AGA 12-compliant retrofit devices.
* AGA Report No. 12, Part 3--"Cryptographic Protection of SCADA Communications: Protection of Networked Systems" will focus on high-speed communication systems, including the Interact.
* AGA Report No. 12, Part 4--"Cryptographic Protection of SCADA Communications: Embedded Protection of SCADA Components" will specify how to protect SCADA systems by incorporating cryptography into the system components at the time of manufacture; this will greatly reduce the cost of protection while improving its performance.
More convenient key management for large-scale operations, protection of data at rest, forensics and intrusion detection, certification, and security policy models are among the issues we hope to address in future extensions of AGA 12.
AGA 12, Part 1
On March 16, 2006, the AGA Managing Committee completed the final balloting on AGA 12, Part 1, making it a gas industry recommended practice. It is available at AGA 12 Web site www.aga.org/Content/ContentGroups/ Operations_and_Engineering2/Infrastructure_ Security 1/AGA 12.pdf
AGA has also offered this as a recommended practice to the water industry and it is posted on the American Water Works Association Research Foundation Web site.
AGA 12, Part 1 is the foundation for the series of four reports and sets forth the general requirements to which the subsequent documents in the series will comply. It begins with a discussion of the cyber threats SCADA systems face. It also includes a collection of background material that specialists in one area need to understand and evaluate the work of specialists in another area. In particular, it explains the basics of cryptography for SCADA experts and the basics of SCADA for cryptographers.
AGA 12, Part 1 recommends adopting a corporate security posture that is based on deploying protection for SCADA communications only where the risks justify doing so. Because SCADA systems differ from one another, the AGA 12 Committee opted to recommend a systematic procedure each system owner can implement to assess its risks, rather than to recommend using a checklist.
The essence of the AGA 12, Part 1 policy recommendation is "determine the possible consequences of an attack on your system and protect only against those attacks that represent unacceptable risks." The report stresses that if the cost of protecting a part of the SCADA system is higher than the risk of an attack, then it makes no sense to deploy protection.
- How to choose the right insurance carrier for your business
- Real Estate: Prepare your properties to weather what lies ahead
- Technology: Be prepared if part of your global supply chain goes missing
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn't Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Content provided in partnership with
Most Recent Business Articles
- Multiple criteria evaluation and optimization of transportation systems
- Multi-criteria analysis procedure for sustainable mobility evaluation in urban areas
- A two-leveled multi-objective symbiotic evolutionary algorithm for the hub and spoke location problem
- Multi-criteria analysis for evaluating the impacts of intelligent speed adaptation
- The development of Taiwan arterial traffic-adaptive signal control system and its field test: a Taiwan experience
Most Recent Business Publications
Most Popular Business Articles
- 7 tips for effective listening: productive listening does not occur naturally. It requires hard work and practice - Back To Basics - effective listening is a crucial skill for internal auditors
- LIFO vs. FIFO: a return to the basics
- FAS 109: a primer for non-accountants - Financial Accounting Standards Board's "Statement 109: Accounting for Income Taxes"
- Too Young to Rent a Car? - 25-years-old the minimum age for car renting - Brief Article
- Design a commission plan that drives sales - Sales Commissions


