1 of 16

CYBER DEFENCE INDIA 2022�WEBINAR PROGRAMME

CRITICAL NATIONAL INFRASTRUCTURE PROTECTION

Maj Gen PK Mallick, VSM (Retd)

CENJOWS

10 June 2022

2 of 16

https://www.strategicstudyindia.com/

3 of 16

USA EXAMPLE

4 of 16

Sector Specific Agency for Each Critical Infrastructure in the USA

5 of 16

Overall Cybersecurity �Organisation of USA

6 of 16

NCCIPC – SIX SECTORS

7 of 16

8 of 16

9 of 16

10 of 16

Questions Regarding Cyber Security Regulators

  • How are the regulators appointed.
  • How are their competencies assessed.
  • Do regulators have a proficient process? Do they possess the technical know-how.
  • Do they have the practical experience to relate to challenges faced by the nuclear sector.
  • What is the process of appointment and evaluation of regulators.
  • Are the regulators consulting vertically and horizontally with other regulators of critical information infrastructure? Who organizes these interactions.
  • What control does National Cyber Security Coordinator has on the regulators.

11 of 16

12 of 16

List of recommendations to secure ICS/SCADA systems

  • Use virtual patching to help manage updates and patches
  • Apply network segmentation
  • Use adequate security measures between the ICS network and corporate network
  • Properly manage authorization and user accounts
  • Use endpoint protection on engineering workstations connected to SCADA for device programming and control adjustments
  • Maintain strict policies for devices that are allowed to connect to SCADA networks
  • Restrict the roles of transitory SCADA nodes to a single purpose
  • Prevent the use of unknown and untrusted USB devices

13 of 16

14 of 16

15 of 16

16 of 16

THANK YOU