CYBERSECURITY ARCHITECTURE DESIGN REVIEW (CADR)

Our OT Security experts will conduct a CADR to ensure that your Oil & Gas network architecture successfully isolates critical OT systems from potential threats and vulnerabilities.Our Operational Technology (OT) experts can strengthen your OT security program by assisting in the evaluation, selection, testing, and implementation of new tools to improve your security posture and address emerging risks.

Ensure Compliance with TSA’s Security Directive through a Cybersecurity Architecture Design Review

As cyber threats increasingly target critical infrastructure, the TSA mandates Cybersecurity Architecture Design Reviews to assess the effectiveness of O&G OT security systems.

Our OT Security experts will conduct a comprehensive review to evaluate your architecture and ensure alignment with industry best practices and frameworks like NIST CSF, NIST 800-53, NIST 800-82, CPwE, and the SANS Five ICS Critical Controls. With our CADR services, we can help your organization:

  • Assess your OT design architecture
  • Verify and validate network traffic
  • Analyze network device configurations and logs
  • Ensure compliance with TSA SD Pipeline-2021-02E

Programmatically Evaluate and Enhance Your OT Security Environment

Our CADR methodology utilizes your preferred framework to assess your O&G OT architecture, configurations, security controls, and interconnectivity. We adopt a Crawl, Walk, Run approach to benchmark cybersecurity maturity.

Our process begins with gathering essential documents such as architecture drawings, asset inventories, network configurations, firewall settings, remote access policies, and OT security procedures.

Next, we conduct comprehensive reviews of network and system design, interview key staff from IT, OT, Security, and Leadership to gather insights, and align our findings with industry best practices. We then provide a detailed CADR Report and briefing, highlighting strengths and opportunities for improving your OT security posture.

Gain Clear Insights into Your OT Security Posture

Each CADR comes with a comprehensive deliverable, outlining the work performed, risk ratings for identified findings, recommended remediation steps, and additional suggestions to bolster your security. Expect the following:

  • Executive Summary: A high-level overview for management, summarizing the findings, risk ratings, and key recommendations to enhance your OT security.
  • Technical Analysis: Detailed insights into your current OT security posture, with specific recommendations to improve security, evidence of observations, and step-by-step procedures for any testing conducted during the assessment (where applicable).