<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Waterfall Security Solutions &#187; Whitepapers and Information</title>
	<atom:link href="http://www.waterfallsecurity.com/category/knowledge/whitepapers/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.waterfallsecurity.com</link>
	<description>Waterfall Security Solutions</description>
	<lastBuildDate>Mon, 30 Jan 2012 12:37:48 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Applying NERC-CIP CAN-0024</title>
		<link>http://www.waterfallsecurity.com/applying-nerc-cip-can-0024/</link>
		<comments>http://www.waterfallsecurity.com/applying-nerc-cip-can-0024/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 05:57:12 +0000</pubDate>
		<dc:creator>amir</dc:creator>
				<category><![CDATA[Whitepapers and Information]]></category>

		<guid isPermaLink="false">http://www.waterfallsecurity.com/?p=3053</guid>
		<description><![CDATA[Under the direction of the Federal Energy Regulatory Commission (FERC), the North American Electric Reliability Corporation (NERC) is charged with enforcing reliability standards for the Bulk Electric System (BES) in North America. Reliability standards for the BES are created under NERC’s supervision by an industry-driven process. Both physical security threats and cyber security threats are [...]]]></description>
			<content:encoded><![CDATA[<p>Under the direction of the Federal Energy Regulatory Commission (FERC), the North American Electric Reliability Corporation (NERC) is charged with enforcing reliability standards for the Bulk Electric System (BES) in North America. Reliability standards for the BES are created under NERC’s supervision by an industry-driven process. <span id="more-3053"></span>Both physical security threats and cyber security threats are regarded as threats to the reliability of the BES, and as a result a set of Critical Infrastructure Protection (CIP) security standards have been adopted.</p>
<p>In December of 2011, NERC issued Compliance Application Notice (CAN) 0024 &#8220;CIP-002 R3 Routable Protocols and Data Diode Devices.&#8221; The purpose of a CAN is to provide guidance to auditors who evaluate industry compliance with CIP reliability standards and who make findings that can lead to enforcement actions and monetary fines. CAN-0024 provides instruction for assessing whether the communication characteristics of data diode devices can be used to exclude cyber assets from consideration as Critical Cyber Assets (CCA) when a routable protocol is used when not at a control center.</p>
<p>&#8220;Data diodes&#8221; are hardware-enforced one-way or unidirectional communications. They permit data to flow from a protected network to an external network, but provide no physical data path for information, remote control attacks, or other cyber-attacks to flow back in to the protected network. Unidirectional hardware is used to provide strong security for connections through an Electronic Security Perimeter (ESP). Routable communications that cross an ESP are of concern under the NERC CIP standards because they can be a vector for attacking a control system.</p>
<p>This whitepaper introduces CIP-002, routable protocols that are used in &#8220;routable communications,&#8221; and unidirectional communication concepts, and then applies the guidance in the CAN-0024 to three types of commonly-deployed hardware architectures for unidirectional communications. We conclude that Waterfall’s Unidirectional Security Gateways, which do not use routable communications, can be used to exclude Cyber Assets from consideration as Critical Cyber Assets (CCA) in accordance with CAN-0024.</p>
<p>January 2012</p>
<p><a href="http://www.waterfallsecurity.com/wp-content/uploads/2012/01/wf-can-24-wp-FINAL-v1.pdf" target="_blank"><img class="alignnone size-full wp-image-1409" title="PDF_logo" src="http://www.waterfallsecurity.com/wp-content/uploads/2009/12/PDF_logo.jpg" alt="" width="47" height="47" />View the article</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/applying-nerc-cip-can-0024/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Recorded Webinar: Strong Cyber Perimeter Protections with Unidirectional Communications</title>
		<link>http://www.waterfallsecurity.com/strong-cyber-perimeter-protections-with-unidirectional-communications-2/</link>
		<comments>http://www.waterfallsecurity.com/strong-cyber-perimeter-protections-with-unidirectional-communications-2/#comments</comments>
		<pubDate>Tue, 10 Jan 2012 07:56:47 +0000</pubDate>
		<dc:creator>amir</dc:creator>
				<category><![CDATA[Whitepapers and Information]]></category>

		<guid isPermaLink="false">http://www.waterfallsecurity.com/?p=2976</guid>
		<description><![CDATA[Unidirectional Gateways transmit business-critical information out of operations networks without introducing any risk to the availability, integrity or safety of control system assets inside those networks. The technology often raises questions, though, when first encountered by security practitioners accustomed to firewalls &#8212; questions of data integrity, remote management, and integration into corporate security systems. However, since [...]]]></description>
			<content:encoded><![CDATA[<p>Unidirectional Gateways transmit business-critical information out of operations networks without introducing any risk to the availability, integrity or safety of control system assets inside those networks. The technology often raises questions, though, when first encountered by security practitioners accustomed to firewalls &#8212; questions of data integrity, remote<span id="more-2976"></span> management, and integration into corporate security systems. However, since Unidirectional Gateways have been deployed successfully at hundreds of sites, and in many industries, there are good answers to all these questions. In the end, Unidirectional Gateways both increase the security of operations networks, and sharply reduce perimeter management costs when compared with conventional firewalls.</p>
<p>This presentation briefly reviews firewall issues and costs, and introduces Unidirectional Gateways. We explore deployment scenarios in refineries and pipelines, and discuss common deployment issues and solutions for them.</p>
<p>Join us to see how network isolation via Unidirectional Gateways permits the flow of critical business information out of control networks, while providing cost savings, as well as strong protections against threats ranging from errors and omissions to insiders, common malware and even targeted attacks.</p>
<p>Waterfall thanks the National Petroleum Refiners Association (NPRA) for sponsoring this webinar and making this recording available.</p>
<p>Press <a href="http://www.waterfallsecurity.com/wp-content/uploads/2012/01/2011-12-06-npra-wf-webinar.wmv" target="_blank"><span style="color: #3366ff;"><strong>here</strong> </span></a>to view the recorded webinar.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/strong-cyber-perimeter-protections-with-unidirectional-communications-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.waterfallsecurity.com/wp-content/uploads/2012/01/2011-12-06-npra-wf-webinar.wmv" length="41818990" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>Recorded Webinar: Strong Cybersecurity: Power Plant Case Study</title>
		<link>http://www.waterfallsecurity.com/recorded-webinar-strong-cybersecurity-power-plant-case-study/</link>
		<comments>http://www.waterfallsecurity.com/recorded-webinar-strong-cybersecurity-power-plant-case-study/#comments</comments>
		<pubDate>Tue, 25 Oct 2011 12:25:24 +0000</pubDate>
		<dc:creator>amir</dc:creator>
				<category><![CDATA[Whitepapers and Information]]></category>

		<guid isPermaLink="false">http://www.waterfallsecurity.com/?p=2789</guid>
		<description><![CDATA[Unidirectional Security Gateways allow data to flow out of protected control networks, but prevent any information or network attacks from flowing back into those networks. While this protects control networks absolutely from external network attacks, it begs questions &#8211; What had to change at the plant to make this work? How did plant personnel react, [...]]]></description>
			<content:encoded><![CDATA[<p>Unidirectional Security Gateways allow data to flow out of protected control networks, but prevent any information or network attacks from flowing back into those networks. While this protects control networks absolutely from external network attacks, it begs questions &#8211; What had to change at the plant to make this work? How did plant personnel react, <span id="more-2789"></span>not just at the time of installation, but months later, once the system had been used for a time?</p>
<p>Dennis Kilgore, President and Founder of DLL Solutions, and Andrew Ginter, Director of Industrial Security at Waterfall Security Solutions explore the threat environment, Unidirectional Security Gateways, and the DLL Solutions experience of installing gateways at a merchant power plant.</p>
<p>Press <a href="http://www.waterfallsecurity.com/wp-content/uploads/2011/11/2011-09-15-wf-dll-webinar.wmv" target="_blank"><span style="color: #3366ff;"><strong>here</strong> </span></a>to view the recorded webinar.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/recorded-webinar-strong-cybersecurity-power-plant-case-study/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.abterra.ca/2011-09-15-wf-dll-webinar.wmv" length="54648615" type="video/x-ms-wmv" />
<enclosure url="http://www.waterfallsecurity.com/wp-content/uploads/2011/11/2011-09-15-wf-dll-webinar.wmv" length="54648615" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>A Realistic Approach for Connecting SCADA/DCS Networks</title>
		<link>http://www.waterfallsecurity.com/a-realistic-approach-for-connecting-scadadcs-networks/</link>
		<comments>http://www.waterfallsecurity.com/a-realistic-approach-for-connecting-scadadcs-networks/#comments</comments>
		<pubDate>Mon, 26 Oct 2009 11:35:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Whitepapers and Information]]></category>

		<guid isPermaLink="false">http://waterfallsecurity.com/?p=338</guid>
		<description><![CDATA[SCADA/DCS networks monitor and control the most valuable assets nationwide and usually refer to operational networks. On the other hand, most of the users are connected through an administrative network which is less sensitive and thus less secure than the operational network. The demand for connecting the networks is required for business continuity reasons and [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-family: Times-Roman;">SCADA/DCS networks monitor and control the most valuable assets nationwide and usually refer to operational networks. On the other hand, most of the users are connected through an administrative network which is less sensitive and thus less secure than the operational network. The demand for connecting the networks is required for <span id="more-338"></span>business continuity reasons and for day by day necessity. The presentation will analyze the threats with regard to networks connectivity and expand the model to other IP based networks. Some solutions will be analyzed and a novel solution will be presented to overcome the network connectivity problem. </span></p>
<p align="left">By Lior Frenkel, Waterfall™ Security Solutions’ co-founder and CTO</p>
<p>Presented at the Entelec Conference, March 2009</p>
<p><a rel="attachment wp-att-1417" href="http://www.waterfallsecurity.com/a-realistic-approach-for-connecting-scadadcs-networks/ppt_logo/"></a></p>
<p><a href="http://waterfallsecurity.com/wp-content/uploads/2009/10/Entelec-2008-Synopsis.pdf" target="_blank"><img class="size-full wp-image-1409 alignleft" title="PDF_logo" src="http://waterfallsecurity.com/wp-content/uploads/2009/12/PDF_logo.jpg" alt="PDF_logo" width="28" height="28" />View the article</a></p>
<p><a href="http://waterfallsecurity.com/wp-content/uploads/2009/10/Entelec-2008-Presentation.pdf" target="_blank"><img class="size-full wp-image-1417 alignleft" title="PPT_logo" src="http://waterfallsecurity.com/wp-content/uploads/2009/12/PPT_logo.jpg" alt="PPT_logo" width="29" height="28" /> View the presentation</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/a-realistic-approach-for-connecting-scadadcs-networks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Waterfall™ for NERC-CIP Compliance</title>
		<link>http://www.waterfallsecurity.com/waterfall-for-nerc-cip-compliance/</link>
		<comments>http://www.waterfallsecurity.com/waterfall-for-nerc-cip-compliance/#comments</comments>
		<pubDate>Mon, 26 Oct 2009 11:36:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Whitepapers and Information]]></category>

		<guid isPermaLink="false">http://waterfallsecurity.com/?p=340</guid>
		<description><![CDATA[ Using Waterfall&#8217;s Unidirectional Security Solution to Achieve True Security &#38; NERC-CIP Compliance
Critical National Infrastructure is under a constant, yet invisible, threat from cyber hacking and cyber terror attempts that are being launched from external networks. These attacks (mainly &#8211; from the Internet) are targeting industrial Process Control Networks (PCN), Supervisory Control and Data Acquisition (SCADA) [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: small;"> </span><strong><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; mso-ascii-theme-font: minor-bidi; mso-hansi-theme-font: minor-bidi; mso-bidi-theme-font: minor-bidi;">Using Waterfall&#8217;s Unidirectional Security Solution to Achieve True Security &amp; NERC-CIP Compliance</span></strong></p>
<p style="text-align: left;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; mso-ascii-theme-font: minor-bidi; mso-hansi-theme-font: minor-bidi; mso-bidi-theme-font: minor-bidi;">Critical National Infrastructure is under a constant, yet invisible, threat from cyber hacking and cyber terror attempts that are being launched from external networks. These attacks (mainly &#8211; from the Internet) are targeting industrial Process Control <span id="more-340"></span>Networks (PCN), Supervisory Control and Data Acquisition (SCADA) Networks and lower level Distributed Control Systems (DCS) and Process Control Systems (PCS) networks. </span></p>
<p style="text-align: left;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; mso-ascii-theme-font: minor-bidi; mso-hansi-theme-font: minor-bidi; mso-bidi-theme-font: minor-bidi;">In the Electricity Utilities’ domain, these critical networks control and operate the very machinery which powers modern day civilization. Throughout North America, electricity utilities are challenged with the task of complying with the reliability standards mandated by NERC (North American Electric Reliability Corporation). </span></p>
<p style="text-align: left;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; mso-ascii-theme-font: minor-bidi; mso-hansi-theme-font: minor-bidi; mso-bidi-theme-font: minor-bidi;">The NERC-CIP (Critical Infrastructure Protection) standards, recently revised in May 2009, provide a cyber security framework for the identification and protection of Critical Cyber Assets to support reliable operation of the Bulk Electric System. The following whitepaper introduces the reader to the Waterfall One-Way™ unidirectional cyber security solution, and explains its ideal fit for achieving both powerful cyber-security as well as NERC-CIP compliance.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt; line-height: normal;">July 09</p>
<p style="text-align: left;"><a href="http://waterfallsecurity.com/wp-content/uploads/2009/10/Waterfall-Paper-for-NERC-Compliance-Ver-6.pdf" target="_blank"><img class="alignnone size-full wp-image-1409" title="PDF_logo" src="http://waterfallsecurity.com/wp-content/uploads/2009/12/PDF_logo.jpg" alt="PDF_logo" width="28" height="28" /> View the article</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/waterfall-for-nerc-cip-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

