Subject

Cybersecurity is the practice of defending computers, servers, mobile devices, electronic systems, networks, and data from malicious hacker attacks.

Industrial cybersecurity plays a vital role in defending critical infrastructure from the growing threat of cyber-attacks.

With the increasing digitisation of industries and the reliance on interconnected systems, safeguarding critical infrastructure has become a top priority for organisations and governments worldwide.

Industrial cyber security encompasses the practices and measures implemented to protect the computer systems, networks, and data that control and operate critical infrastructure in industries such as energy, transportation, manufacturing, and healthcare. It safeguards these systems from unauthorised access, disruption, or manipulation, ensuring essential services’ smooth functioning and preventing potential disasters.

Cybersecurity plays a vital role in today’s interconnected world. As industries become increasingly reliant on digital technologies, the risk of cyber-attacks on critical infrastructure increases.

This is why an implementation of proper industrial cyber security systems plays a significant role in protecting our society.

Applied standards

IEC 62443 is a series of standards for cybersecurity that address security for automation and control systems of industrial objects. The series is divided into different sections and describes both technical and process-related aspects of automation and control systems security. The series include the following documents:

IEC 62443-1-1    Concepts and models   

IEC 62443-1-5    Scheme for IEC 62443 security profiles

IEC 62443-2-1    Security program requirements for IACS asset owners  

IEC 62443-2-3    Patch management in the IACS environment

IEC 62443-2-4    Requirements for IACS service providers

IEC 62443-3-1    Security technologies for industrial automation and control systems

IEC 62443-3-2    Security risk assessment and system design

IEC 62443-3-3    System security requirements and security levels

IEC 62443-4-1    Secure product development lifecycle requirements

IEC 62443-4-2    Technical security requirements for IACS components

IEC 62443-6-1    Security evaluation methodology for IEC 62443-2-4

The mentioned standards address the implications for several principal roles that use a risk-based approach to prevent and manage security risks in their specific activities:

  • Asset Owner
  • Product Supplier
  • Service Providers

The standards contain requirements for systems and products that are evaluated by four so-called security levels. The different levels indicate the resistance against different classes of attackers including:

  • Security Level 0: No special requirement or protection required
  • Security Level 1: Protection against unintentional or accidental misuse
  • Security Level 2: Protection against intentional misuse by simple means with few resources, general skills and low motivation
  • Security Level 3: Protection against intentional misuse by sophisticated means with moderate resources, automation-specific knowledge and moderate motivation
  • Security Level 4: Protection against intentional misuse using sophisticated means with extensive resources, automation-specific knowledge and high motivation

Our services

The SSA provides high quality services of Certification of secure product development lifecycle based on IEC 62443-4-1. The service will include a complex of onsite and off-site assessment of how organisation develops and follows the product development lifecycle that ensure the cybersecurity by design.