Abstract:
With the spread of the WannaCry virus in 2017, CSN raised an alert to the risks of cyberattacks in industrial environments. Given the above, there were several internal actions supported by suppliers for disinfecting contaminated computers. CSN is a company with a high level of criticality, possessing critical mission equipment that, in the event of a successful cyberattack, could be misused, resulting in damages to both the population and the organization.
In critical mission industrial environments where continuous operation is essential, network security plays a fundamental role in protecting vital assets and mitigating cyber risks. In this challenging scenario, the deployment of a Security Operations Center (SOC) becomes an urgent necessity to monitor, detect, and respond to cyber threats in real time. Claroty, as a solution tailored for the industry and with its expertise in industrial security, emerges as an indispensable support tool in building and operating an effective SOC for mission-critical industrial environments.
In conjunction with the study of SOC deployment, the following environment management tools were implemented:
• Monitoring through Zabbix software;
• Inventory and asset management with GLPI software;
• Network documentation with NETBOX software;
• Log consolidation through GrayLog;
These tools play an indispensable role in managing asset documentation and inventory in the operational technology (OT) environment. With online monitoring, the maintenance team has accurate information on all monitored equipment. Through this information, greater assertiveness and agility are achieved in problem-solving, as the knowledge of network assets and traffic behavior within the monitored environment simplifies issue resolution.