Subject
Cybersecurity is the practice of defending computers, servers, mobile devices, electronic systems, networks, and data from malicious hacker attacks.
Industrial cybersecurity plays a vital role in defending critical infrastructure from the growing threat of cyber-attacks.
With the increasing digitisation of industries and the reliance on interconnected systems, safeguarding critical infrastructure has become a top priority for organisations and governments worldwide.
Industrial cyber security encompasses the practices and measures implemented to protect the computer systems, networks, and data that control and operate critical infrastructure in industries such as energy, transportation, manufacturing, and healthcare. It safeguards these systems from unauthorised access, disruption, or manipulation, ensuring essential services’ smooth functioning and preventing potential disasters.
Cybersecurity plays a vital role in today’s interconnected world. As industries become increasingly reliant on digital technologies, the risk of cyber-attacks on critical infrastructure increases.
This is why an implementation of proper industrial cyber security systems plays a significant role in protecting our society.
Applied standards
IEC 62443 is a series of standards for cybersecurity that address security for automation and control systems of industrial objects. The series is divided into different sections and describes both technical and process-related aspects of automation and control systems security. The series include the following documents:
IEC 62443-1-1 Concepts and models
IEC 62443-1-5 Scheme for IEC 62443 security profiles
IEC 62443-2-1 Security program requirements for IACS asset owners
IEC 62443-2-3 Patch management in the IACS environment
IEC 62443-2-4 Requirements for IACS service providers
IEC 62443-3-1 Security technologies for industrial automation and control systems
IEC 62443-3-2 Security risk assessment and system design
IEC 62443-3-3 System security requirements and security levels
IEC 62443-4-1 Secure product development lifecycle requirements
IEC 62443-4-2 Technical security requirements for IACS components
IEC 62443-6-1 Security evaluation methodology for IEC 62443-2-4
The mentioned standards address the implications for several principal roles that use a risk-based approach to prevent and manage security risks in their specific activities:
- Asset Owner
- Product Supplier
- Service Providers
The standards contain requirements for systems and products that are evaluated by four so-called security levels. The different levels indicate the resistance against different classes of attackers including:
- Security Level 0: No special requirement or protection required
- Security Level 1: Protection against unintentional or accidental misuse
- Security Level 2: Protection against intentional misuse by simple means with few resources, general skills and low motivation
- Security Level 3: Protection against intentional misuse by sophisticated means with moderate resources, automation-specific knowledge and moderate motivation
- Security Level 4: Protection against intentional misuse using sophisticated means with extensive resources, automation-specific knowledge and high motivation
Our services
The SSA provides high quality services of Certification of secure product development lifecycle based on IEC 62443-4-1. The service will include a complex of onsite and off-site assessment of how organisation develops and follows the product development lifecycle that ensure the cybersecurity by design.
Links
- PD IEC/TS 62443-1-1:2009 - Industrial communication networks. Network and system security Terminology, concepts and models
- PD IEC TS 62443-1-5:2023 - Security for industrial automation and control systems Scheme for IEC 62443 security
- IEC 62443-2-1:2024 Ed. 2.0 - Security for industrial automation and control systems - Part 2-1: Security program requirements for IACS asset
- PD IEC/TR 62443-2-3:2015 - Security for industrial automation and control systems Patch management in the IACS environment
- IEC 62443-2-4:2023 Ed. 2.0 - Security for industrial automation and control systems - Part 2-4: Security program requirements for IACS service providers
- PD IEC/TR 62443-3-1:2009 - Industrial communication networks. Network and system security Security technologies for industrial automation and control systems
- IEC 62443-3-2:2020 Ed. 1.0 - Security for industrial automation and control systems - Part 3-2: Security risk assessment for system design
- IEC 62443-3-3:2013 Ed. 1.0 - Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels
- IEC 62443-4-1:2018 Ed. 1.0 - Security for industrial automation and control systems - Part 4-1: Secure product development lifecycle requirements
- IEC 62443-4-2:2019 Ed. 1.0 - Security for industrial automation and control systems - Part 4-2: Technical security requirements for IACS components
- IEC TS 62443-6-1:2024 Ed. 1.0 - Security for industrial automation and control systems - Part 6-1: Security evaluation methodology for IEC 62443-2-4