Experts Urge CISA to Set Clear Rules for Protecting Operational Technology in Federal Agencies
The Operational Technology Cybersecurity Coalition, a group of cyber firms and critical infrastructure operators, has set out its views on what the US Cybersecurity and Infrastructure Security Agency (CISA) should require of federal agencies to protect operational technology (OT). OT covers the systems that control physical equipment, and the push follows this summer's attacks on water utilities. The coalition says a binding operational directive should name who is responsible for protecting OT at each agency, draw on existing federal guidelines and set minimum security practices.
The coalition points to several gaps: CISA has limited visibility into the range of OT devices used across federal agencies, security policies are inconsistent, and the consequences of an attack could be severe. A Government Accountability Office report published last month found that most civilian federal agencies have not put in place 2023 requirements for networked Internet of Things and OT devices. The coalition notes that CISA lacks a full view of agency assets and risks, such as connected programmable logic controllers.
Coalition policy director Michael Garcia said the effort has two aims. First, it would ensure the government follows its own advice. Second, it would signal to the private sector what matters, so owners and operators know what to ask of their providers. He noted that thousands of federal properties use OT for functions from power supply to heating and air conditioning, though some systems may be minor.