IndustrialCyber

ISA and OTCC join forces to advance standards-based OT cybersecurity across critical infrastructure


The International Society of Automation (ISA), a professional society for automation and the Operational Technology Cybersecurity Coalition (OTCC), a coalition working to improve operational technology (OT) cybersecurity through open, vendor-neutral collaboration, have announced their intention to collaborate to help strengthen OT cybersecurity across critical infrastructure.

The two organizations have signed a Memorandum of Understanding (MOU) to work together on initiatives that raise awareness of OT cybersecurity risks and solutions, explore strategic issues of shared interest, and facilitate technical engagement between members of each organization. The goal is to encourage better implementation and recognition of foundational cybersecurity standards like ISA/IEC 62443, the globally recognized consensus-based series of OT cybersecurity standards developed by ISA.

“Protecting critical infrastructure requires sustained collaboration, practical guidance and a shared commitment to standards-based cybersecurity,” said Claire Fallon, CEO of ISA. “This partnership creates an important framework for ISA and OTCC to help advance key OT cybersecurity practices.”

“ISA and OTCC come at OT cybersecurity from different angles — ISA through the standards that define good practice, OTCC through the companies putting them to work,” said Tatyana Bolton, Executive Director of OTCC. “Bringing those perspectives together is how standards move from paper into practice, and we look forward to working with ISA to make that happen.”

OTCC recently published a position paper advocating for a single, horizontal standard for OT cybersecurity rather than a patchwork of sector-specific mandates. The paper recommends that ISA/IEC 62443 be recognized as the global OT security standard. It names ISA/IEC 62443 as an established framework uniquely situated to harmonize around, as this standard has been specifically tailored to meet the requirements of OT. 

With one interoperable OT cybersecurity standard such as ISA/IEC 62443, the OTCC paper argues, the burden of adhering to duplicative standards can be reduced, helping to ensure critical infrastructure and industrial operations stay resilient everywhere.

The partnership comes amid growing pressure on U.S. critical infrastructure operators to strengthen OT cybersecurity after cyberattacks disrupted water and wastewater systems in at least seven states, including more than 30 water systems in Minnesota. 

The OTCC has argued that repeated advisories and voluntary guidance are no longer sufficient, calling on CISA to issue a Binding Operational Directive establishing baseline OT cybersecurity controls across federal civilian networks. The coalition has also urged Congress to restore funding for the State and Local Cybersecurity Grant Program and provide long-term authorization for the Cybersecurity Information Sharing Act of 2015, which it says are critical to helping smaller communities and infrastructure operators improve resilience against increasingly capable cyber threats.



Source link