Fri, May 8

CISA Report on the need for Zero Trust protection in Operational Technology

This CISA report describing the need for Zero Trust protections in Operational Technology is especially profound for the Electric Grid as more Inverter Based Resource (IBR) are being installed that require Internet access for command and control functions. Zero Trust protection will ensure that only registered, trusted entities are allowed to access an IBR command and control function.

CISAZeroTrustOT.pdf
1.05MB

Similar Guidance is also provided by Australia.

A description of Zero Trust (Never infer trust, always verify trust) is described in this posting using an airport analogy to describe how Zero Trust works in cyberspace;

https://www.linkedin.com/feed/update/urn:li:activity:7457528519401742336/

An IETF Internet-Draft URI scheme, called ztdnaid, has been submitted to support the implementation described above in the airport analogy. Working similar to a traveler presenting a Passport to a TSA Agent before being granted access to the gate area, a Zero Trust check is performed whenever an Entity requests services from a cyber Resource must present their ztdnaid to the Gateway protecting a Resource where it is validated as trustworthy and allowed to access the resource.

3