<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Waterfall Security Solutions</title>
	<atom:link href="http://www.waterfallsecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.waterfallsecurity.com</link>
	<description>Waterfall Security Solutions</description>
	<lastBuildDate>Mon, 30 Jan 2012 12:37:48 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Applying NERC-CIP CAN-0024</title>
		<link>http://www.waterfallsecurity.com/applying-nerc-cip-can-0024/</link>
		<comments>http://www.waterfallsecurity.com/applying-nerc-cip-can-0024/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 05:57:12 +0000</pubDate>
		<dc:creator>amir</dc:creator>
				<category><![CDATA[Whitepapers and Information]]></category>

		<guid isPermaLink="false">http://www.waterfallsecurity.com/?p=3053</guid>
		<description><![CDATA[Under the direction of the Federal Energy Regulatory Commission (FERC), the North American Electric Reliability Corporation (NERC) is charged with enforcing reliability standards for the Bulk Electric System (BES) in North America. Reliability standards for the BES are created under NERC’s supervision by an industry-driven process. Both physical security threats and cyber security threats are [...]]]></description>
			<content:encoded><![CDATA[<p>Under the direction of the Federal Energy Regulatory Commission (FERC), the North American Electric Reliability Corporation (NERC) is charged with enforcing reliability standards for the Bulk Electric System (BES) in North America. Reliability standards for the BES are created under NERC’s supervision by an industry-driven process. <span id="more-3053"></span>Both physical security threats and cyber security threats are regarded as threats to the reliability of the BES, and as a result a set of Critical Infrastructure Protection (CIP) security standards have been adopted.</p>
<p>In December of 2011, NERC issued Compliance Application Notice (CAN) 0024 &#8220;CIP-002 R3 Routable Protocols and Data Diode Devices.&#8221; The purpose of a CAN is to provide guidance to auditors who evaluate industry compliance with CIP reliability standards and who make findings that can lead to enforcement actions and monetary fines. CAN-0024 provides instruction for assessing whether the communication characteristics of data diode devices can be used to exclude cyber assets from consideration as Critical Cyber Assets (CCA) when a routable protocol is used when not at a control center.</p>
<p>&#8220;Data diodes&#8221; are hardware-enforced one-way or unidirectional communications. They permit data to flow from a protected network to an external network, but provide no physical data path for information, remote control attacks, or other cyber-attacks to flow back in to the protected network. Unidirectional hardware is used to provide strong security for connections through an Electronic Security Perimeter (ESP). Routable communications that cross an ESP are of concern under the NERC CIP standards because they can be a vector for attacking a control system.</p>
<p>This whitepaper introduces CIP-002, routable protocols that are used in &#8220;routable communications,&#8221; and unidirectional communication concepts, and then applies the guidance in the CAN-0024 to three types of commonly-deployed hardware architectures for unidirectional communications. We conclude that Waterfall’s Unidirectional Security Gateways, which do not use routable communications, can be used to exclude Cyber Assets from consideration as Critical Cyber Assets (CCA) in accordance with CAN-0024.</p>
<p>January 2012</p>
<p><a href="http://www.waterfallsecurity.com/wp-content/uploads/2012/01/wf-can-24-wp-FINAL-v1.pdf" target="_blank"><img class="alignnone size-full wp-image-1409" title="PDF_logo" src="http://www.waterfallsecurity.com/wp-content/uploads/2009/12/PDF_logo.jpg" alt="" width="47" height="47" />View the article</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/applying-nerc-cip-can-0024/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Recorded Webinar: Strong Cyber Perimeter Protections with Unidirectional Communications</title>
		<link>http://www.waterfallsecurity.com/strong-cyber-perimeter-protections-with-unidirectional-communications-2/</link>
		<comments>http://www.waterfallsecurity.com/strong-cyber-perimeter-protections-with-unidirectional-communications-2/#comments</comments>
		<pubDate>Tue, 10 Jan 2012 07:56:47 +0000</pubDate>
		<dc:creator>amir</dc:creator>
				<category><![CDATA[Whitepapers and Information]]></category>

		<guid isPermaLink="false">http://www.waterfallsecurity.com/?p=2976</guid>
		<description><![CDATA[Unidirectional Gateways transmit business-critical information out of operations networks without introducing any risk to the availability, integrity or safety of control system assets inside those networks. The technology often raises questions, though, when first encountered by security practitioners accustomed to firewalls &#8212; questions of data integrity, remote management, and integration into corporate security systems. However, since [...]]]></description>
			<content:encoded><![CDATA[<p>Unidirectional Gateways transmit business-critical information out of operations networks without introducing any risk to the availability, integrity or safety of control system assets inside those networks. The technology often raises questions, though, when first encountered by security practitioners accustomed to firewalls &#8212; questions of data integrity, remote<span id="more-2976"></span> management, and integration into corporate security systems. However, since Unidirectional Gateways have been deployed successfully at hundreds of sites, and in many industries, there are good answers to all these questions. In the end, Unidirectional Gateways both increase the security of operations networks, and sharply reduce perimeter management costs when compared with conventional firewalls.</p>
<p>This presentation briefly reviews firewall issues and costs, and introduces Unidirectional Gateways. We explore deployment scenarios in refineries and pipelines, and discuss common deployment issues and solutions for them.</p>
<p>Join us to see how network isolation via Unidirectional Gateways permits the flow of critical business information out of control networks, while providing cost savings, as well as strong protections against threats ranging from errors and omissions to insiders, common malware and even targeted attacks.</p>
<p>Waterfall thanks the National Petroleum Refiners Association (NPRA) for sponsoring this webinar and making this recording available.</p>
<p>Press <a href="http://www.waterfallsecurity.com/wp-content/uploads/2012/01/2011-12-06-npra-wf-webinar.wmv" target="_blank"><span style="color: #3366ff;"><strong>here</strong> </span></a>to view the recorded webinar.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/strong-cyber-perimeter-protections-with-unidirectional-communications-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.waterfallsecurity.com/wp-content/uploads/2012/01/2011-12-06-npra-wf-webinar.wmv" length="41818990" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>The 12th Annual Herzliya Conference – 2012, January 30-February 2</title>
		<link>http://www.waterfallsecurity.com/the-12th-annual-herzliya-conference-%e2%80%93-2012-january-30-february-2/</link>
		<comments>http://www.waterfallsecurity.com/the-12th-annual-herzliya-conference-%e2%80%93-2012-january-30-february-2/#comments</comments>
		<pubDate>Wed, 25 Jan 2012 15:24:14 +0000</pubDate>
		<dc:creator>amir</dc:creator>
				<category><![CDATA[2012]]></category>

		<guid isPermaLink="false">http://www.waterfallsecurity.com/?p=3058</guid>
		<description><![CDATA[ 
About the conference:
The Herzliya Conference, the flagship event of the Institute for Policy and Strategy at IDC Herzliya, is a year-long work cycle consisting of the following phases: 

Preliminary research and analysis conducted by the Herzliya Taskforces and commissioned experts; 
The Conference, at which major policy statements and initiatives are delivered, and Herzliya Roundtables are held, followed [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-3059" title="Herzliya-Conference-Header" src="http://www.waterfallsecurity.com/wp-content/uploads/2012/01/Herzliya-Conference-Header.png" alt="" width="251" height="122" /> </p>
<p><strong>About the conference:</strong></p>
<p>The Herzliya Conference, the flagship event of the Institute for Policy and Strategy at IDC Herzliya, is a year-long work cycle consisting of the following phases: <span id="more-3058"></span></p>
<ul>
<li><strong><em>Preliminary research and analysis</em></strong> conducted by the <strong><em>Herzliya Taskforces </em></strong>and commissioned experts; </li>
<li><strong><em>The Conference</em></strong>, at which major policy statements and initiatives are delivered, and <strong><em>Herzliya Roundtables</em></strong> are held, followed by deliberations and the presentation of specially commissioned reports and studies; </li>
<li><strong><em>Executive Herzliya Reports</em></strong> presented to key policy-makers, summarizing the Conference’s proceedings, findings, and major policy recommendations.  </li>
</ul>
<p><strong>Conference links:</strong><strong></strong></p>
<p><a href="http://www.herzliyaconference.org/eng/" target="_blank">Conference Website</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/the-12th-annual-herzliya-conference-%e2%80%93-2012-january-30-february-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NEI &#8211; Cyber Security Implementation Workshop, January 31-February 2</title>
		<link>http://www.waterfallsecurity.com/nei-cyber-security-implementation-workshop/</link>
		<comments>http://www.waterfallsecurity.com/nei-cyber-security-implementation-workshop/#comments</comments>
		<pubDate>Sun, 25 Dec 2011 13:51:38 +0000</pubDate>
		<dc:creator>amir</dc:creator>
				<category><![CDATA[2012]]></category>

		<guid isPermaLink="false">http://www.waterfallsecurity.com/?p=2959</guid>
		<description><![CDATA[
About the conference:
The U.S. Nuclear Regulatory Commission has approved the Cyber Security Plans and Implementation Schedules for all currently operating commercial nuclear power reactors in the United States.  The NEI Cyber Security Implementation Workshop will assist licensees in implementing the requirements of the Plan and in meeting the milestones in the Implementation Schedule. 
Attendance at day [...]]]></description>
			<content:encoded><![CDATA[<p><strong><img class="alignnone size-full wp-image-1857" title="NEI_logo" src="http://www.waterfallsecurity.com/wp-content/uploads/2010/04/NEI_logo.PNG" alt="" width="180" height="109" /></strong></p>
<p><strong>About the conference:</strong></p>
<p>The U.S. Nuclear Regulatory Commission has approved the Cyber Security Plans and Implementation Schedules for all currently operating commercial nuclear power reactors in the United States.  The NEI Cyber Security Implementation <span id="more-2959"></span>Workshop will assist licensees in implementing the requirements of the Plan and in meeting the milestones in the Implementation Schedule. </p>
<p>Attendance at day one of the Workshop is restricted to employees of nuclear power plant utilities.  Others will not be permitted to register or attend.  Day one will focus on the activities associated with implementing milestones from the Implementation Schedule that are due to be completed by December 31, 2012. The format will be small break-out sessions that will focus on each of the seven milestones.  Session leaders will facilitate in-depth discussion regarding milestone implementation strategies, acceptance criteria, guidance for conducting audits and assessments, and preparing for inspections of the program. </p>
<p>Days two and three will be open for general attendance, and will include presentations, panel discussions, and exhibitor fire-talks. </p>
<p><strong>Conference links:</strong> </p>
<p><a href="http://www.nei.org/newsandevents/conferencesandmeetings/csw" target="_blank">Conference Website </a></p>
<p><a href="https://register.nei.org/registration/LogIn/login.aspx?ReturnUrl=%2fregistration%2fconference%2fregistrationprocessoverview.aspx%3fid%3d67&amp;id=67" target="_blank">Registration</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/nei-cyber-security-implementation-workshop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Smart Grid Cyber Security Virtual Summit 2012, February 2</title>
		<link>http://www.waterfallsecurity.com/smart-grid-cyber-security-virtual-summit-2012-february-2/</link>
		<comments>http://www.waterfallsecurity.com/smart-grid-cyber-security-virtual-summit-2012-february-2/#comments</comments>
		<pubDate>Sun, 08 Jan 2012 06:50:36 +0000</pubDate>
		<dc:creator>amir</dc:creator>
				<category><![CDATA[2012]]></category>

		<guid isPermaLink="false">http://www.waterfallsecurity.com/?p=2978</guid>
		<description><![CDATA[
About the conference:
Securing the End-to-End Smart Grid Ecosystem 
In the year since Stuxnet first struck, cyber security has become of critical concern for utilities. Securing the emerging smart grid must be an end-to-end, architectural undertaking built into all facets of IT, OT, ICS, communications and infrastructure. Introducing intelligence and two-way communication into the utility network [...]]]></description>
			<content:encoded><![CDATA[<p><strong><img class="alignnone size-full wp-image-2981" title="Smart-Grid-Virtual-Summit2012" src="http://www.waterfallsecurity.com/wp-content/uploads/2012/01/Smart-Grid-Virtual-Summit2012.png" alt="" width="493" height="61" /></strong></p>
<p><strong>About the conference:</strong></p>
<p><strong>Securing the End-to-End Smart Grid Ecosystem </strong></p>
<p>In the year since Stuxnet first struck, cyber security has become of critical concern for utilities. Securing the <span id="more-2978"></span>emerging smart grid must be an end-to-end, architectural undertaking built into all facets of IT, OT, ICS, communications and infrastructure. Introducing intelligence and two-way communication into the utility network means opening the door to vulnerability, and utilities must proceed with caution.</p>
<p>Organized by The Smart Grid Observer, the one day, 100% online <strong>Smart Grid Cyber Security Virtual Summit</strong> features a series of in-depth presentations designed to examine the very latest technologies, deployment strategies, best practices, and lessons learned in making smart grid security a reality. Critical questions addressed include:</p>
<ul>
<li>Where are the most significant weak points in the smart grid&#8217;s security? How should we address them?</li>
<li>What is the current nature of the cyber security threat? What do we need to worry about?</li>
<li>What are the latest NERC CIP requirements and how best to comply?</li>
<li>What are the key technology enablers and advances for smart grid cyber security?</li>
<li>What are the best practices and strategies for securing AMI?</li>
<li>How can utilities effectively go about securing software and embedded devices designed for the smart grid?</li>
</ul>
<p>Topics to be addressed include:</p>
<p>&#8211; Securing the end-to-end smart grid ecosystem &#8212; the big picture<br />
&#8211; Safeguarding customer data and privacy<br />
&#8211; Security systems integration and interoperability<br />
&#8211; Evaluating, measuring, and testing smart grid security systems<br />
&#8211; Standards update and trends<br />
&#8211; Lessons from the trenches: utility cyber security case studies<br />
&#8211; Managing potential security exposure &#8212; determining limits<br />
&#8211; HAN security<br />
&#8211; Latest vendor offerings and components<br />
&#8211; Regulatory trends, developments, and expectations<br />
&#8211; Crossing organizational silos to ensure smart grid security<br />
&#8211; Network monitoring and anomaly detection</p>
<p><strong>Conference links:</strong> </p>
<p><a href="http://www.smartgridobserver.com/index-csvs.htm" target="_blank">Conference Website </a></p>
<p><a href="http://www.smartgridobserver.com/register-csvs.htm" target="_blank">Registration</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/smart-grid-cyber-security-virtual-summit-2012-february-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CyberSec 2012, February 12</title>
		<link>http://www.waterfallsecurity.com/cybersec-2012-february-12/</link>
		<comments>http://www.waterfallsecurity.com/cybersec-2012-february-12/#comments</comments>
		<pubDate>Sun, 15 Jan 2012 07:42:32 +0000</pubDate>
		<dc:creator>amir</dc:creator>
				<category><![CDATA[2012]]></category>

		<guid isPermaLink="false">http://www.waterfallsecurity.com/?p=3017</guid>
		<description><![CDATA[
About the conference:
CyberSec, the international information cyber security conference, interacts companies, organizations and governmental bodies with cyber security experts to discuss latest developments in protecting enterprises from upcoming threats.
Topics:
-New techniques in enterprises cyber protection
-Avoiding APT best practices
-Meeting social attacks challenges
-Cloud cyber implications
-Israel 2012 &#8211; cyber security for business, governmental and defense segments
-Legal implications with cyber [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-3030" title="Cyber-Sec-2012" src="http://www.waterfallsecurity.com/wp-content/uploads/2012/01/Cyber-Sec-2012.png" alt="" width="353" height="83" /></p>
<p><strong>About the conference:</strong></p>
<p>CyberSec, the international information cyber security conference, interacts companies, organizations and governmental bodies with cyber security experts to discuss latest developments in protecting enterprises from upcoming <span id="more-3017"></span>threats.</p>
<p>Topics:</p>
<p>-New techniques in enterprises cyber protection<br />
-Avoiding APT best practices<br />
-Meeting social attacks challenges<br />
-Cloud cyber implications<br />
-Israel 2012 &#8211; cyber security for business, governmental and defense segments<br />
-Legal implications with cyber crime and cyber warfare</p>
<p><strong>Conference links:</strong> </p>
<p><a href="http://cybersec.events.co.il/save-the-date" target="_blank">Conference Website </a></p>
<p><a href="https://events.co.il/join?redirected_from=cybersec&amp;registration=true" target="_blank">Registration</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/cybersec-2012-february-12/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VirtualH2O 2012, February 21</title>
		<link>http://www.waterfallsecurity.com/virtualh2o-2012-february-21/</link>
		<comments>http://www.waterfallsecurity.com/virtualh2o-2012-february-21/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 10:02:49 +0000</pubDate>
		<dc:creator>amir</dc:creator>
				<category><![CDATA[2012]]></category>

		<guid isPermaLink="false">http://www.waterfallsecurity.com/?p=3071</guid>
		<description><![CDATA[
About the conference:
PennWell Corporation, publisher of WaterWorld, Industrial WaterWorld, and Water &#38; Wastewater International magazines, will once again host its completely online water industry conference and exhibition, VirtualH2O, on February 21, 2012 (8:00AM &#8211; 6:00PM ET).
VirtualH2O combines virtual tradeshow exhibits and conference presenations to deliver attendees an innovative &#8212; and convenient &#8212; opportunity to network [...]]]></description>
			<content:encoded><![CDATA[<p><strong><img class="alignnone size-full wp-image-3072" title="Virtual-H2O" src="http://www.waterfallsecurity.com/wp-content/uploads/2012/01/Virtual-H2O.png" alt="" width="300" height="103" /></strong></p>
<p><strong>About the conference:</strong><strong></strong></p>
<p>PennWell Corporation, publisher of <em>WaterWorld</em>, <em>Industrial WaterWorld</em>, and <em>Water &amp; Wastewater International</em> magazines, will once again host its completely online water industry conference and exhibition, VirtualH<sub>2</sub>O, <span id="more-3071"></span>on February 21, 2012 (8:00AM &#8211; 6:00PM ET).</p>
<p>VirtualH<sub>2</sub>O combines virtual tradeshow exhibits and conference presenations to deliver attendees an innovative &#8212; and convenient &#8212; opportunity to network with and learn from leaders in the water and wastewater industries.</p>
<p><strong>Conference Program:</strong></p>
<p>VirtualH<sub>2</sub>O offers attendees access to an expansive array of conference presenations addressing important topics in municipal drinking water, municipal wastewater, industrial water/wastewater, urban water management, and municipal water utility management.<br />
Visitors who attend an entire presentation &#8212; even during the archive period &#8212; will receive a certificate of attendance, which can be used to apply for Professional Development Hours (PDH) with their respective state organizations.</p>
<p><strong>Conference links:</strong><strong> </strong></p>
<p><a href="http://www.virtualh2oevent.com/index.html" target="_blank">Conference Website</a></p>
<p><a href="https://presentations.inxpo.com/Shows/Pennwell/H20/02-12/Registration/registration.html" target="_blank">Registration</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/virtualh2o-2012-february-21/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security of IT and IC Systems at Nuclear Facilities, February 27-29</title>
		<link>http://www.waterfallsecurity.com/security-of-it-and-ic-systems-at-nuclear-facilities-february-27-29/</link>
		<comments>http://www.waterfallsecurity.com/security-of-it-and-ic-systems-at-nuclear-facilities-february-27-29/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 12:09:01 +0000</pubDate>
		<dc:creator>amir</dc:creator>
				<category><![CDATA[2012]]></category>

		<guid isPermaLink="false">http://www.waterfallsecurity.com/?p=3080</guid>
		<description><![CDATA[
About the conference:
 The World Institute for Nuclear Security (WINS, Atomic Energy of Canada Limited (AECL), Bruce Power and Ontario Power Generation (OPG) are pleased to announce an International Best Practice Workshop on Security of Information Technology (IT) and Instrumentation and Control (IC) Systems.
This workshop will take place at the Delta Chelsea Hotel in Toronto, Ontario, [...]]]></description>
			<content:encoded><![CDATA[<p><strong><img class="alignnone size-full wp-image-3083" title="WINS-Header" src="http://www.waterfallsecurity.com/wp-content/uploads/2012/01/WINS-Header.png" alt="" width="275" height="91" /></strong></p>
<p><strong>About the conference:</strong><strong></strong></p>
<p> The World Institute for Nuclear Security (WINS, Atomic Energy of Canada Limited (AECL), Bruce Power and Ontario Power Generation (OPG) are pleased to <span id="more-3080"></span>announce an International Best Practice Workshop on Security of Information Technology (IT) and Instrumentation and Control (IC) Systems.</p>
<p>This workshop will take place at the Delta Chelsea Hotel in Toronto, Ontario, Canada on the 27th -29th of February 2012.</p>
<p><strong>Conference links:</strong><strong> </strong></p>
<p><a href="http://www.waterfallsecurity.com/wp-content/uploads/2012/01/Workshop-Cyber-Security-Announcement.pdf" target="_blank">Conference Announcement</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/security-of-it-and-ic-systems-at-nuclear-facilities-february-27-29/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2012 AFPM Security Conference &amp; Exhibition, February 27-29</title>
		<link>http://www.waterfallsecurity.com/2012-afpm-security-conference-exhibition-february-27-29/</link>
		<comments>http://www.waterfallsecurity.com/2012-afpm-security-conference-exhibition-february-27-29/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 12:37:24 +0000</pubDate>
		<dc:creator>amir</dc:creator>
				<category><![CDATA[2012]]></category>

		<guid isPermaLink="false">http://www.waterfallsecurity.com/?p=3091</guid>
		<description><![CDATA[
About the conference:
As an industry and as a nation, we must keep our sites secure and informed about the many changing threats to our critical infrastructure. The threats are diverse and increasing and could change the way refiners and petrochemical manufacturers operate. The conference presents current topics of critical importance to assist attendees in keeping themselves [...]]]></description>
			<content:encoded><![CDATA[<p><strong><img class="alignnone size-full wp-image-3094" title="2012-AFPM-Conference" src="http://www.waterfallsecurity.com/wp-content/uploads/2012/01/2012-AFPM-Conference.png" alt="" width="201" height="108" /></strong></p>
<p><strong>About the conference:</strong><strong></strong></p>
<p>As an industry and as a nation, we must keep our sites secure and informed about the many changing threats to our critical infrastructure. The threats are diverse and<span id="more-3091"></span> increasing and could change the way refiners and petrochemical manufacturers operate. The conference presents current topics of critical importance to assist attendees in keeping themselves up to date on national critical infrastructure security issues&#8212;from terrorism to oil field crimes to DHS regulations and policies!</p>
<p>Don’t miss this great opportunity to meet with key government contacts, network with industry security experts and hear from national authorities on the terrorist threat the industry faces today.</p>
<p><strong>Conference links:</strong><strong> </strong></p>
<p><a href="http://www2.afpm.org/forms/meeting/Microsite/SC12" target="_blank">Conference Website</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/2012-afpm-security-conference-exhibition-february-27-29/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Diode Devices Secure Systems</title>
		<link>http://www.waterfallsecurity.com/data-diode-devices-secure-systems/</link>
		<comments>http://www.waterfallsecurity.com/data-diode-devices-secure-systems/#comments</comments>
		<pubDate>Sun, 29 Jan 2012 13:03:36 +0000</pubDate>
		<dc:creator>amir</dc:creator>
				<category><![CDATA[Press Release 2012]]></category>

		<guid isPermaLink="false">http://www.waterfallsecurity.com/?p=3067</guid>
		<description><![CDATA[
“You can’t attack, if you can’t communicate” is how Andrew Ginter sees it.
This is the concept of unidirectional gateways. There’s a security perimeter around your asset whatever it may be, a factory, a process, a data farm, whatever. Then there’s the outside world of threat, crime, and destruction.
Unidirectional gateways allow one-way communication only over the [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-2829" title="ISS-Source" src="http://www.waterfallsecurity.com/wp-content/uploads/2011/10/ISS-Source.png" alt="" width="286" height="52" /></p>
<p>“You can’t attack, if you can’t communicate” is how Andrew Ginter sees it.</p>
<p>This is the concept of unidirectional gateways. There’s a security perimeter around your asset whatever it may be, a factory, a process, a data farm, whatever. Then there’s the outside world of threat, crime, and destruction.</p>
<p>Unidirectional gateways allow one-way communication only over the <span id="more-3067"></span>void where firewalls exist and where firewalls can fail. “Firewalls are only software,” said Ginter, director of industrial security at Waterfall Security Solutions. “Stuxnet could not have spread over the data diodes operating in a unidirectional gateway.”</p>
<p>The only communication to the outside world (the business network, for example) is data moving in one direction and that direction is out of the protected area. Moreover, that is data only, no code, no logic, no compromising intelligence.</p>
<p>Ginter talked about that topic and more during a Tuesday webinar entitled, “NERC Issues CAN-0024: Guidance for Unidirectional, Routable Communications” with Mark Simon, senior consultant with Encari a critical infrastructure protection-consulting firm, and Joel Langill, chief technology officer at SCADAhacker.</p>
<p>NERC has issued CAN-0024, which provides guidance to NERC-CIP auditors as to when unidirectional communications equipment or “data diodes” must come into consideration to facilitate “routable communications.”</p>
<p>NERC is the North American Electric Reliability Corporation. Its mission is to ensure the reliability of the North American bulk power system. CIP stands for critical infrastructure protection.</p>
<p>CAN is Compliance Application Notice and CAN-0024 is “Routable Protocols and Data Diode Devices.”</p>
<p>An increasing number of NERC entities are deploying unidirectional communications equipment, because such equipment provides stronger security to protected cyber assets than firewalls can provide.</p>
<p>“Unidirectional communications enable sandboxing,” Ginter said.</p>
<p>Sandboxing is creating confined execution environments. A sandbox limits, or reduces, the level of access its applications have. In effect, it is a container. Therefore, the scope of potential damage caused by a malicious entity within is minimal.</p>
<p>The CAN-0024 guidance makes it clear that some deployments use routable protocols, and other deployments do not. In some cases, this distinction influences which cyber assets are technically Critical Cyber Assets.</p>
<p>The best discussion of the security advantages of this technology and for helpful visuals and graphics, click here for Ginter’s white paper.</p>
<p><a href="http://www.isssource.com/data-diode-devices-secure-systems/" target="_blank">View the article</a></p>
<p>By Nicholas Sheble</p>
<p>ISS Source, January 25, 2012</p>
]]></content:encoded>
			<wfw:commentRss>http://www.waterfallsecurity.com/data-diode-devices-secure-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

