Waterfall Security Solutions Passes INL Cyber Security Assessment

Waterfall Security Solutions, provider of Unidirectional Security Gateways, announced recently the successful completion of a security assessment, undertaken by the Idaho National Laboratory, of Waterfall's Unidirectional Security Gateway's technology and products. The assessment was conducted as part of the Department of Homeland Security Control Systems Security Program (CSSP).

The whole process, originating in 2009, was successfully concluded in July 2010, when INL released the final assessment report.

The assessment verified that the Waterfall system provides one-way communications between two different security zones. The physics of the system prevent any data transmission from the low security enclave to the high security enclave. Waterfall's methodology of protecting an industrial network from an external connection in a lower security zone was verified by the assessment.

The assessment identified three software vulnerabilities, all associated with the software interfaces between the Waterfall gateway and third party applications. Obviously, as the security of the Waterfall product is built on a sound and verified physical basis, no vulnerability, including the three identified, can allow an attacker to move "upstream" from the Receive side to the Transmit side.

Waterfall's patented cyber security solutions enable Utilities and Critical Infrastructures to securely connect their critical industrial networks to external networks, thus securely fulfilling their business needs without exposing these networks to risks and threats of cyber-attacks, cyber terror and hacking from the external, less secure networks. Waterfall's cyber security solutions assists Utilities and Critical Infrastructures to achieve compliance with NERC-CIP, NRC, CFATS and other regulations and standards, as well as cyber-security policies and best-practices.

The final report also provided recommendations on measures that could further enhance the overall security of the product. Waterfall will shortly begin a second evaluation phase, where these recommendations and other enhancements are planned to be implemented.

"It was an honor being part of such a process, having our technology assessed by the cyber security experts at INL. This process is part with Waterfall's strategy of a wide and open cooperation with vendors, regulators, customers and other third parties. We welcome anyone wishing to evaluate our technology or assess our products," said Lior Frenkel, co-founder and CEO of Waterfall Security Solutions, "Our large and expanding installed based in North America, will appreciate the added confidence provided by an INL cyber security assessment."

Featured

  • Gaining a Competitive Edge

    Ask most companies about their future technology plans and the answers will most likely include AI. Then ask how they plan to deploy it, and that is where the responses may start to vary. Every company has unique surveillance requirements that are based on market focus, scale, scope, risk tolerance, geographic area and, of course, budget. Those factors all play a role in deciding how to configure a surveillance system, and how to effectively implement technologies like AI. Read Now

  • 6 Ways Security Awareness Training Empowers Human Risk Management

    Organizations are realizing that their greatest vulnerability often comes from within – their own people. Human error remains a significant factor in cybersecurity breaches, making it imperative for organizations to address human risk effectively. As a result, security awareness training (SAT) has emerged as a cornerstone in this endeavor because it offers a multifaceted approach to managing human risk. Read Now

  • The Stage is Set

    The security industry spans the entire globe, with manufacturers, developers and suppliers on every continent (well, almost—sorry, Antarctica). That means when regulations pop up in one area, they often have a ripple effect that impacts the entire supply chain. Recent data privacy regulations like GDPR in Europe and CPRA in California made waves when they first went into effect, forcing businesses to change the way they approach data collection and storage to continue operating in those markets. Even highly specific regulations like the U.S.’s National Defense Authorization Act (NDAA) can have international reverberations – and this growing volume of legislation has continued to affect global supply chains in a variety of different ways. Read Now

  • Access Control Technology

    As we move swiftly toward the end of 2024, the security industry is looking at the trends in play, what might be on the horizon, and how they will impact business opportunities and projections. Read Now

Featured Cybersecurity

Webinars

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions. 3