Field Notes
Blog
- Active vs. passive vulnerability assessment in OTActive scanning finds vulnerabilities by interacting with a target. Passive assessment finds them by watching what's already there. In OT, the choice between the two isn't a preference, it's a constraint, and each has real blind spots.
- Cybersecurity Assessment Plan: preparing for the annual cycleSD Pipeline-2021-02G requires a Cybersecurity Assessment Plan, submitted annually, that proves the Implementation Plan actually works. What the schedule requires, what counts as an assessment method, and what the annual report has to say.
- What a Pipeline Cybersecurity Coordinator is actually responsible forSD Pipeline-2021-01G requires a named Cybersecurity Coordinator and an alternate. The designation itself is administrative. What the role does afterward is where programs succeed or stall.
- Cybersecurity Implementation Plan: what operators must maintainTSA approval of a Cybersecurity Implementation Plan isn't the finish line. SD Pipeline-2021-02G requires the plan to stay current, and sets specific deadlines for reporting the changes that keep it that way.
- IT/OT segmentation for pipeline environmentsMost pipeline networks aren't unsegmented on paper. They're unsegmented in practice, one historian export or remote-access jump host at a time. What the zone-and-conduit model actually requires, and where real segmentation projects usually find the gap.
- Pipeline cybersecurity incident response: IT and OT considerationsSD Pipeline-2021-02G requires an Incident Response Plan built around four specific objectives, one of them explicitly about isolating IT from OT. What that means in practice, and why the same containment step reads differently on each side of the boundary.
- How to prepare leadership for a TSA cybersecurity assessmentThe Cybersecurity Coordinator can produce every document TSA asks for and the meeting can still go sideways if the executives in the room can't speak to the program behind the paperwork. What leadership actually needs to know going in.
- Why a routine IT scan can take down an RTUActive vulnerability scanning is standard IT hygiene. Pointed at an OT network, the same scan can trip a control outage, and NIST 800-82r3 explains why the two environments need different playbooks.