Developing a Cybersecurity Plan of Action: Lessons Learned From Our Pipeline Customers
ID: e396ef27-fdee-5f78-87b5-2498dc8a2082
STIX ID: report--e396ef27-fdee-5f78-87b5-2498dc8a2082
Feed Name: Dragos Blog
Executive summary: In response to recent high-profile attacks and TSA guidance, Dragos outlines an initiative to improve pipeline OT/ICS cybersecurity by validating security architecture and strengthening incident response. The report describes a four-part assessment methodology—Crown Jewel Analysis, program review, topology review, and a Collection Management Framework—to ensure visibility, appropriate logging, and actionable detection; it also recommends customized tabletop exercises, mission-focused passive solutions (Dragos Platform, Neighborhood Keeper), data ownership and anonymization practices, and alignment with standards such as MITRE ATT&CK for ICS, referencing ONG-SCC resources for pipeline-specific guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
