A panel discussion with representatives from ISASecure, UL and an ICS vendor discuss:
what type of certification is of most value: application/device, system or vendor?
is a low bar / relatively simple to pass test certification worthwhile or misleading?
is source code evaluation for a security certification practical? How will this work in the environment of significantly reduced development cycle times?
is a system certification possible? is a product certification of value if it is only one component of a system that is not certified? Bryan brings up a good analogy with auto safety systems
why would an asset owner want a certified system, eg better security, regulation, insurability?
is there a successful security certification effort that ICS can learn from or mimic? or certification programs we should not copy? Cloud service certifications were given as an example.
would you buy a toaster if it were not certified?
what happens when a researcher exploits a certified product or system?
Moderator: Dale Peterson, Digital Bond
Panelists: Ken Modeste of UL, Paul Forney of Schneider Electric, Bryan Owen of OSIsoft