Security for industrial automation and control systems - Part 2-4: Security program requirements for IACS service providers

IEC 62443-2:2023 specifies a comprehensive set of requirements for security-related processes that IACS service providers can offer to the asset owner during integration and maintenance activities of an Automation Solution. Because not all requirements apply to all industry groups and organizations, Subclause 4.1.4 provides for the development of "profiles" that allow for the subsetting of these requirements. Profiles are used to adapt this document to specific environments, including environments not based on an IACS. NOTE 1 The term "Automation Solution" is used as a proper noun (and therefore capitalized) in this document to prevent confusion with other uses of this term. Collectively, the security processes offered by an IACS service provider are referred to as its Security Program (SP) for IACS asset owners. In a related specification, IEC 62443-2-1 describes requirements for the Security Management System of the asset owner. NOTE 2 In general, these security capabilities are policy, procedure, practice and personnel related. Figure 1 illustrates the integration and maintenance security processes of the asset owner, service provider(s), and product supplier(s) of an IACS and their relationships to each other and to the Automation Solution. Some of the requirements of this document relating to the safety program are associated with security requirements described in IEC 62443-3-3 and IEC 62443-4-2. NOTE 3 The IACS is a combination of the Automation Solution and the organizational measures necessary for its design, deployment, operation, and maintenance. NOTE 4 Maintenance of legacy system with insufficient security technical capabilities, implementation of policies, processes and procedures can be addressed through risk mitigation.

IT-Sicherheit für industrielle Automatisierungssysteme - Teil 2-4: Anforderungen an das IT-Sicherheitsprogramm von Dienstleistern für industrielle Automatisierungssysteme

Sécurité des automatismes industriels et des systèmes de commande - Partie 2-4: Exigences de programme de sécurité pour les fournisseurs de service IACS

L’IEC 62453-2:2023 fournit des informations sur l’intégration de la technologie CIP™ dans la spécification des interfaces des outils des dispositifs de terrain (FDT) (IEC 62453-2). La Famille de profils de communication 2 (communément appelée CIP™ définit des profils de communication basés sur les normes IEC 61158‑2 Type 2, IEC 61158‑3‑2, IEC 61158‑4‑2, IEC 61158‑5‑2, IEC 61158‑6‑2 et IEC 62026‑3. Les profils de base CP 2/1 (ControlNet™), CP 2/2 (EtherNet/IP™) et CP 2/3 (DeviceNet™1) sont définis dans l’IEC 61784-1 et l’IEC 61784-2. Un Profil de communication supplémentaire (CompoNet™1), également basé sur CIP™, est défini dans l’IEC 62026-7. La présente partie de l’IEC 62453 spécifie les services de communication et autres services. La présente spécification ne contient pas la spécification des outils FDT et ne la modifie pas.CIP™ (Common Industrial Protocol), DeviceNet™ et CompoNet™ sont les appellations commerciales de Open DeviceNet Vendor Association, Inc (ODVA). Cette information est donnée à l’intention des utilisateurs du présent document et ne signifie nullement que l’IEC approuve ou recommande le détenteur de la marque ou de l’un quelconque de ses produits. La conformité à la présente norme n’exige pas l’emploi des appellations commerciales CIP™, DeviceNet™ ou CompoNet™. L’utilisation des appellations commerciales CIP™, DeviceNet™ ou CompoNet™ nécessite l’autorisation de Open DeviceNet Vendor Association, Inc. ControlNet™ est l’appellation commerciale de ControlNet International, Ltd. Cette information est donnée à l’intention des utilisateurs du présent document et ne signifie nullement que l’IEC approuve ou recommande le détenteur de la marque ou de l’un quelconque de ses produits. La conformité à ce profil n’exige pas l’emploi de l’appellation commerciale ControlNet™. L’utilisation de l’appellation commerciale ControlNet™ nécessite l’autorisation de ControlNet International, Ltd. EtherNet/IP™ est l’appellation commerciale de ControlNet International, Ltd et de Open DeviceNet Vendor Association, Inc. Cette information est donnée à l’intention des utilisateurs du présent document et ne signifie nullement que l’IEC approuve ou recommande le détenteur de la marque ou de l’un quelconque de ses produits. La conformité à ce profil n’exige pas l’emploi de l’appellation commerciale EtherNet/IP™. L’utilisation de l’appellation commerciale EtherNet/IP™ nécessite l’autorisation de ControlNet International, Ltd. ou de Open DeviceNet Vendor Association, Inc.

Zaščita industrijske avtomatizacije in nadzornih sistemov - 2-4. del: Zahteve za program zaščite za ponudnike storitev IACS (IEC 62443-2-4:2023)

General Information

Status
Published
Publication Date
25-Jan-2024
Current Stage
6060 - Document made available - Publishing
Start Date
26-Jan-2024
Completion Date
26-Jan-2024

Relations

Buy Standard

Draft
prEN IEC 62443-2-4:2022 - BARVE
English language
93 pages
sale 10% off
Preview
sale 10% off
Preview
e-Library read for
1 day

Standards Content (Sample)


SLOVENSKI STANDARD
oSIST prEN IEC 62443-2-4:2022
01-november-2022
Zaščita industrijske avtomatizacije in nadzornih sistemov - 2-4. del: Zahteve za
program varnosti zaščite za ponudnike storitev IACS
Security for industrial automation and control systems - Part 2-4: Security program
requirements for IACS service providers
IT-Sicherheit für industrielle Automatisierungssysteme - Teil 2-4: Anforderungen an das
IT-Sicherheitsprogramm von Dienstleistern für industrielle Automatisierungssysteme
Sécurité des automatismes industriels et des systèmes de commande - Partie 2-4:
Exigences de programme de sécurité pour les fournisseurs de service IACS
Ta slovenski standard je istoveten z: prEN IEC 62443-2-4:2022
ICS:
25.040.01 Sistemi za avtomatizacijo v Industrial automation
industriji na splošno systems in general
35.030 Informacijska varnost IT Security
oSIST prEN IEC 62443-2-4:2022 en,fr,de
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

oSIST prEN IEC 62443-2-4:2022
oSIST prEN IEC 62443-2-4:2022
65/936/CDV
COMMITTEE DRAFT FOR VOTE (CDV)
PROJECT NUMBER:
IEC 62443-2-4 ED2
DATE OF CIRCULATION: CLOSING DATE FOR VOTING:
2022-09-09 2022-12-02
SUPERSEDES DOCUMENTS:
65/848/CD, 65/854A/CC
IEC TC 65 : INDUSTRIAL-PROCESS MEASUREMENT, CONTROL AND AUTOMATION
SECRETARIAT: SECRETARY:
France Mr Didier GIARRATANO
OF INTEREST TO THE FOLLOWING COMMITTEES: PROPOSED HORIZONTAL STANDARD:

TC 44,SC 45A,TC 57,SC 62A,SC 121A,ISO/IEC
JTC 1/SC 41
Other TC/SCs are requested to indicate their interest, if
any, in this CDV to the secretary.
FUNCTIONS CONCERNED:
EMC ENVIRONMENT QUALITY ASSURANCE SAFETY
SUBMITTED FOR CENELEC PARALLEL VOTING NOT SUBMITTED FOR CENELEC PARALLEL VOTING
Attention IEC-CENELEC parallel voting
The attention of IEC National Committees, members of
CENELEC, is drawn to the fact that this Committee Draft
for Vote (CDV) is submitted for parallel voting.
The CENELEC members are invited to vote through the
CENELEC online voting system.
This document is still under study and subject to change. It should not be used for reference purposes.
Recipients of this document are invited to submit, with their comments, notification of any relevant patent rights of
which they are aware and to provide supporting documentation.

TITLE:
Security for industrial automation and control systems - Part 2-4: Security program
requirements for IACS service providers

PROPOSED STABILITY DATE: 2025
NOTE FROM TC/SC OFFICERS:
electronic file, to make a copy and to print out the content for the sole purpose of preparing National Committee positions.
You may not copy or "mirror" the file or printed version of the document, or any part of it, for any other purpose without
permission in writing from IEC.

oSIST prEN IEC 62443-2-4:2022
– 2 – IEC CDV 62443-2-4 © IEC 2022
1 CONTENTS
2 CONTENTS . 2
3 FOREWORD . 3
4 INTRODUCTION . 5
5 Scope . 6
6 Normative references . 7
7 Terms, definitions, abbreviated terms and acronyms . 7
8 3.1 Terms and definitions. 7
9 3.2 Abbreviations . 11
10 Concepts . 12
11 4.1 Use of IEC 62443-2-4 . 12
12 4.1.1 Use of IEC 62443-2-4 by service providers . 12
13 4.1.2 Use of IEC 62443-2-4 by asset owners . 13
14 4.1.3 Use of IEC 62443-2-4 during negotiations between asset owners and
15 IACS service providers . 14
16 4.1.4 Profiles . 14
17 4.1.5 Integration service providers . 15
18 4.1.6 Maintenance service providers . 15
19 4.2 Maturity model . 16
20 Requirements overview . 18
21 5.1 Contents . 18
22 5.2 Sorting and filtering . 18
23 5.3 IEC 62264-1 hierarchy model . 18
24 5.4 Requirements table columns . 18
25 5.5 Column definitions . 19
26 5.5.1 Req ID column . 19
27 5.5.2 BR/RE column . 19
28 5.5.3 Functional area column . 20
29 5.5.4 Topic column . 21
30 5.5.5 Subtopic column . 21
31 5.5.6 Documentation column . 23
32 5.5.7 Requirement description column . 23
33 5.5.8 Rationale column . 23
34 Annex A (normative) Security requirements . 24
35 Bibliography . 92
37 Figure 1 – Scope of service provider capabilities . 7
39 Table 1 – Maturity levels . 17
40 Table 2 – Columns . 18
41 Table 3 – Functional area column values . 20
42 Table 4 – Topic column values . 21
43 Table 5 – Subtopic column values . 22
44 Table A.1 – Security program requirements . 25
Internal
oSIST prEN IEC 62443-2-4:2022
IEC CDV 62443-2-4 © IEC 2022
– 3 –
47 INTERNATIONAL ELECTROTECHNICAL COMMISSION
49 ____________
51 SECURITY FOR INDUSTRIAL AUTOMATION
52 AND CONTROL SYSTEMS –
54 Part 2-4: Security program requirements
55 for IACS service providers
57 Ed.2
59 FOREWORD
60 1) The International Electrotechnical Commission (IEC) is a worldwide organization for standardization comprising
61 all national electrotechnical committees (IEC National Committees). The object of IEC is to promote international
62 co-operation on all questions concerning standardization in the electrical and electronic fields. To this end and
63 in addition to other activities, IEC publishes International Standards, Technical Specifications, Technical Reports,
64 Publicly Available Specifications (PAS) and Guides (hereafter referred to as “IEC Publication(s)”). Their
65 preparation is entrusted to technical committees; any IEC National Committee interested in the subject dealt with
66 may participate in this preparatory work. International, governmental and non-governmental organizations liaising
67 with the IEC also participate in this preparation. IEC collaborates closely with the International Organization for
68 Standardization (ISO) in accordance with conditions determined by agreement between the two organizations.
69 2) The formal decisions or agreements of IEC on technical matters express, as nearly as possible, an international
70 consensus of opinion on the relevant subjects since each technical committee has representation from all
71 interested IEC National Committees.
72 3) IEC Publications have the form of recommendations for international use and are accepted by IEC National
73 Committees in that sense. While all reasonable efforts are made to ensure that the technical content of IEC
74 Publications is accurate, IEC cannot be held responsible for the way in which they are used or for any
75 misinterpretation by any end user.
76 4) In order to promote international uniformity, IEC National Committees undertake to apply IEC Publications
77 transparently to the maximum extent possible in their national and regional publications. Any divergence between
78 any IEC Publication and the corresponding national or regional publication shall be clearly indicated in the latter.
79 5) IEC itself does not provide any attestation of conformity. Independent certification bodies provide conformity
80 assessment services and, in some areas, access to IEC marks of conformity. IEC is not responsible for any
81 services carried out by independent certification bodies.
82 6) All users should ensure that they have the latest edition of this publication.
83 7) No liability shall attach to IEC or its directors, employees, servants or agents including individual experts and
84 members of its technical committees and IEC National Committees for any personal injury, property damage or
85 other damage of any nature whatsoever, whether direct or indirect, or for costs (including legal fees) and
86 expenses arising out of the publication, use of, or reliance upon, this IEC Publication or any other IEC
87 Publications.
88 8) Attention is drawn to the Normative references cited in this publication. Use of the referenced publications is
89 indispensable for the correct application of this publication.
90 9) Attention is drawn to the possibility that some of the elements of this IEC Publication may be the subject of patent
91 rights. IEC shall not be held responsible for identifying any or all such patent rights.
92 International Standard IEC 62443-2-4 Ed. 2 has been prepared by IEC technical committee 65:
93 Industrial-process measurement, control and automation in collaboration with the liaison
94 International Instrumentation Users Association, referred to as the WIB from its original and
95 now obsolete Dutch name.
96 This publication has been drafted in accordance with the ISO/IEC Directives, Part 2.
97 A list of all parts in the IEC 62443 series, published under the general title Security for industrial
98 automation and control systems, can be found on the IEC website.
99 Edition 2 of IEC 62443-2-4 makes editorial corrections discovered since its release and provides
100 clarifications that have been identified as necessary, primarily through the use of the document
101 during conformity assessment and during the development of profiles. One area of clarification

Internal
oSIST prEN IEC 62443-2-4:2022
– 4 – IEC CDV 62443-2-4 © IEC 2022
102 is that some requirements were interpreted as technical requirements, when the intention was
103 for them to be the use/configuration of technical capabilities.
104 Future standards in this series will carry the new general title as cited above. Titles of existing
105 standards in this series will be updated at the time of the next edition.
106 The committee has decided that the contents of the base publication and its amendment will
107 remain unchanged until the stability date indicated on the IEC web site under
108 "http://webstore.iec.ch" in the data related to the specific publication. At this date, the
109 publication will be
110 • reconfirmed,
111 • withdrawn,
112 • replaced by a revised edition, or
113 • amended.
IMPORTANT – The 'colour inside' logo on the cover page of this publication indicates
that it contains colours which are considered to be useful for the correct understanding
of its contents. Users should therefore print this document using a colour printer.
Internal
oSIST prEN IEC 62443-2-4:2022
IEC CDV 62443-2-4 © IEC 2022
– 5 –
116 INTRODUCTION
117 This standard is the part of the IEC 62443 series that contains security requirements for
118 providers of integration and maintenance services for Industrial Automation and Control
119 Systems (IACS).
Internal
oSIST prEN IEC 62443-2-4:2022
– 6 – IEC CDV 62443-2-4 © IEC 2022
122 SECURITY FOR INDUSTRIAL AUTOMATION
123 AND CONTROL SYSTEMS –
125 Part 2-4: Security program requirements
126 for IACS service providers
128 Ed.2
130 1 Scope
131 This part of IEC 62443 specifies a comprehensive set of requirements for security capabilities
132 for IACS service providers that they can offer to the asset owner during integration and
133 maintenance activi
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.