Taking our head out of the sand – Challenges of Operational Technology Security at an Airport
Télécharger les ressourcesÀ propos de cette session
Andrew Faber, responsable des risques de sécurité TI à l'Autorité aéroportuaire du Grand Toronto, décrit les technologies opérationnelles de Toronto Pearson : plus de 12 500 caméras et automates générant l'essentiel du trafic réseau, éclairage de pistes dans le nuage, eaux pluviales, dégivrage, train sans conducteur, cogénération et 30 kilomètres de convoyeurs à bagages. Après un survol des incidents récents, il cite Mandiant : les brèches en TO sont des crimes d'opportunité fondés sur des accès distants mal sécurisés et des systèmes exposés non corrigés. Ses six « pourquoi » : des cycles de vie de plusieurs décennies contre des correctifs mensuels, des TO désormais bâties sur des piles TI et du Bluetooth, ingénieurs et gens de sécurité sans langage commun, des RSSI qui relèvent du DPI sans posséder une seule pompe, des tests de « chemin heureux » qui craignent les balayages de vulnérabilités, la perte de l'isolement au profit du nuage et de l'accès distant, et la chaîne d'approvisionnement. La GTAA répond par la responsabilité partagée, le personnel TO dans le processus de risque, le cadre de Dragos, des politiques et une architecture TO, et un partenariat pluriannuel plutôt qu'un achat d'outil.
IT Security staff have grown up in a world of patch management, mirrored test environments, DMZs and defense in depth. We have code and penetration testing to find security concerns with deployments. We have mature frameworks with NIST, PCI and ISO to guide our way to establish risk appetites and identify improvements needed. The world of Operational Technology is difficult for an IT Security practitioner to understand and work within given its different objectives, culture and background. Toronto Pearson airport is currently in a operational technology shift which is challenging our business, our IT security department and our management. I will highlight this progression of this technology and culture shift and provide our learnings and pitfalls. My goal is to provide you with our experience as we mature the technology security in our operational environment at the airport.
À retenir
- Inscrire le soutien de sécurité sur tout le cycle de vie dans les contrats TO : savoir combien de temps le fournisseur fournira des correctifs, et prévoir mises à niveau, fenêtres d'essai et retour arrière dès le départ.
- Intégrer les ingénieurs TO au processus de risque cyber; ils détiennent le volet impact et sécurité des personnes que les TI ne peuvent pas évaluer seules.
- Éliminer d'abord les accès distants mal sécurisés (TeamViewer, PC Anywhere, RDP sur Internet); Mandiant voit la plupart des brèches TO commencer là ou sur des systèmes exposés non corrigés.
- Refuser l'argument du fournisseur voulant que « le réseau TO assure la sécurité »; exiger que l'application elle-même résiste à un test d'intrusion avant de l'exposer.
- N'acheter des outils de surveillance TO qu'avec un changement de gens et de processus, sinon le constat d'audit obtient un tableau de bord et aucune réduction du risque.
Conférenciers

Andrew Faber is the Director, IT Security Risk Management at the Greater Toronto Airports Authority (GTAA), operator of Toronto Pearson International, Canada’s largest airport. Andrew is responsible for the GTAA’s information security services… Lire la suiteRéduire
Andrew Faber is the Director, IT Security Risk Management at the Greater Toronto Airports Authority (GTAA), operator of Toronto Pearson International, Canada’s largest airport. Andrew is responsible for the GTAA’s information security services organization and oversees the team that not only develops the organization’s information security strategy and roadmap, but also manages delivery of that strategy through IT Security governance and awareness training. A key element of Andrew’s role consists of ensuring that an appropriate cyber security incident response plan is both in place and well aligned with the airport’s overall incident response plan. Throughout his career, Andrew has successfully developed and delivered information security roadmaps for a number of organizations across multiple industries, including financial services, health care, retail and telecommunications. Andrew holds both a CISSP certification from ISC2 and an ABCP certification from the Disaster Recovery Institute in Canada. Prior to joining the GTAA, Andrew was the Director of Information Security for Aimia (Aeroplan) responsible for the company’s Canadian business units. Andrew has also specialized in the Payment Card Industry Compliance program as a certified auditor.

