I have been contracted to perform a security risk assessment that relates specifically to ICS and SCADA systems. I have performed many IT security risk assessments, however, I am new to assessing these types of environments specifically. I am familiar with ICS like devices and I believe I have a cursory understanding of functionality and some of their inherent challenges.
My question is for those who do this everyday, work in such an environment or have assessed an ICS environment before.
Are there specific tools that are useful in this type of assessment that are not obvious? I have done some searching and have read through the NIST standards for assessing ICS. I have also found the DHS tool CSET (which looks to be more of a self-assessment tool, but may have some useful features like the diagramming tool).
Also, is there a specific standard that is generally followed for this type of engagement?
Before anyone steps up on their security guy soapbox, this entity is well aware that this is my first ICS engagement and that I have been assessing unique IT environments for many years. I also have strong back-support from my team that is highly experienced in this type of engagement. I'm sure they will have many ideas for me as well, I just wanted to put this out there for public comment.
Thanks!
Reader's Digest:
What specific tools exist for Scada / ICS assessment?
What specific standards are generally acceptable for a Scada / ICS risk assessment?