Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Mitigations
  3. Human User Authentication

Human User Authentication

Require user authentication before allowing access to data or accepting commands to a device. While strong multi-factor authentication is preferable, it is not always feasible within ICS environments. Performing strong user authentication also requires additional security controls and processes which are often the target of related adversarial techniques (e.g., Valid Accounts, Default Credentials). Therefore, associated ATT&CK mitigations should be considered in addition to this, includingMulti-factor Authentication,Account Use Policies,Password Policies,User Account Management,Privileged Account Management, andUser Account Control.

ID: M0804
Security Controls: IEC 62443-3-3:2013 - SR 1.1, IEC 62443-4-2:2019 - CR 1.1, NIST SP 800-53 Rev. 5 - IA-2
Version: 1.1
Created: 11 September 2020
Last Modified: 20 October 2023
ICS Layer
downloadview

Techniques Addressed by Mitigation

DomainIDNameUse
ICST0800Activate Firmware Update Mode

Devices that allow remote management of firmware should require authentication before allowing any changes. The authentication mechanisms should also supportAccount Use Policies,Password Policies, andUser Account Management

ICST0858Change Operating Mode

All field controllers should require users to authenticate for all remote or local management sessions. The authentication mechanisms should also supportAccount Use Policies,Password Policies, andUser Account Management.

ICST0885Commonly Used Port

All field controllers should require users to authenticate for all remote or local management sessions. The authentication mechanisms should also supportAccount Use Policies,Password Policies, andUser Account Management.

ICST0868Detect Operating Mode

All field controllers should require users to authenticate for all remote or local management sessions. The authentication mechanisms should also supportAccount Use Policies,Password Policies, andUser Account Management.

ICST0816Device Restart/Shutdown

All field controllers should require users to authenticate for all remote or local management sessions. The authentication mechanisms should also supportAccount Use Policies,Password Policies, andUser Account Management.

ICST0871Execution through API

All APIs on remote systems or local processes should require the authentication of users before executing any code or system changes.

ICST0838Modify Alarm Settings

All field controllers should require users to authenticate for all remote or local management sessions. The authentication mechanisms should also supportAccount Use Policies,Password Policies, andUser Account Management.

ICST0821Modify Controller Tasking

All field controllers should require users to authenticate for all remote or local management sessions. The authentication mechanisms should also support Account Use Policies, Password Policies, and User Account Management.

ICST0836Modify Parameter

All field controllers should require that user authenticate for all remote or local management sessions. The authentication mechanisms should also support Account Use Policies, Password Policies, and User Account Management.

ICST0889Modify Program

All field controllers should require users to authenticate for all remote or local management sessions. The authentication mechanisms should also support Account Use Policies, Password Policies, and User Account Management.

ICST0839Module Firmware

Devices that allow remote management of firmware should require authentication before allowing any changes. The authentication mechanisms should also supportAccount Use Policies,Password Policies, andUser Account Management.

ICST0861Point & Tag Identification

All field controllers should require users to authenticate for all remote or local management sessions. The authentication mechanisms should also supportAccount Use Policies,Password Policies, andUser Account Management.

ICST0843Program Download

All field controllers should require users to authenticate for all remote or local management sessions. The authentication mechanisms should also supportAccount Use Policies,Password Policies, andUser Account Management.

ICST0845Program Upload

All field controllers should require users to authenticate for all remote or local management sessions. The authentication mechanisms should also supportAccount Use Policies,Password Policies, andUser Account Management.

ICST0886Remote Services

All remote services should require strong authentication before providing user access.

ICST0857System Firmware

Devices that allow remote management of firmware should require authentication before allowing any changes. The authentication mechanisms should also supportAccount Use Policies,Password Policies, andUser Account Management.

×

[8]ページ先頭

©2009-2026 Movatter.jp