General Information

Abstract

IEC TR 63486:2024 provides a cybersecurity framework for digital I&C programmable systems [2]. IEC 62645 [1] aligns strongly with the information security management system (ISMS) elements detailed within ISO/IEC 27001:2013 [2]. The ISO/IEC ISMS structure corresponds to the “I&C digital programmable system cybersecurity program” in the context (as defined in 5.2.1 of IEC 62645:2019 [1]).
The scope of this document is to capture the national and international cyber-risk approaches employed to manage cybersecurity risks associated with Instrumentation and Control (I&C) and Electrical Power Systems (EPS) at a Nuclear Power Plant (NPP).
This document summarizes an evaluation of cyber-risk approaches that are in use by nuclear facility operators to manage cybersecurity risks.
The scope of this document generally follows the exclusions of IEC 62645 which are:
- Non-malevolent actions and events such as accidental failures, human errors (except those stated above, such as impacting the performance of cybersecurity controls), and natural events. In particular, good practices for managing applications and data, including backup and restoration related to accidental failure, are out of scope.
This document summarizes key insights of the international and cyber-risk approaches used at NPPs regarding the application of ISO/IEC 27005:2018 [5]. The evaluation is based on 11 challenges to cybersecurity risk management and their applicability to NPP risk management. The challenges are detailed in Clause 7. This document also relates the risk management elements of IEC 62645 and IEC 63096.

Status
Published
Publication Date
12-Sep-2024
Current Stage
PPUB - Publication issued
Start Date
13-Sep-2024
Completion Date
19-Jul-2024

Buy Documents

Technical report

IEC TR 63486:2024 - Nuclear facilities - Instrumentation, control and electrical power systems - Cybersecurity risk management approaches

ISBN:978-2-8322-9380-5
English language (160 pages)
sale 15% off
Preview
sale 15% off
Preview

Overview - IEC TR 63486:2024 (Nuclear facilities - Cybersecurity risk management approaches)

IEC TR 63486:2024 provides a consolidated cybersecurity risk management framework tailored for digital Instrumentation & Control (I&C) programmable systems and Electrical Power Systems (EPS) at Nuclear Power Plants (NPPs). The technical report summarizes international and national cyber‑risk approaches used by nuclear facility operators and maps those approaches to established information security guidance such as ISO/IEC 27005:2018 and the I&C cybersecurity program concepts in IEC 62645. The document evaluates practical applicability through a set of identified cyber‑risk challenges and presents cross‑references and implementation insights (see Clauses 6–7 and informative Annexes).

Key topics and technical focus

  • Scope and limitations
    • Focuses on malevolent cybersecurity risks to I&C and EPS at NPPs.
    • Excludes non‑malevolent events (accidental failures, ordinary human error, natural events) and routine backup/restore practices.
  • Risk management mapping
    • Aligns ISMS structure elements (ISO/IEC 27001) and information risk guidance (ISO/IEC 27005) with nuclear I&C cybersecurity program requirements defined in IEC 62645.
  • Eleven NPP cyber‑risk challenges
    • The report analyzes 11 challenges (e.g., interdependencies, vulnerability uncertainty, adversary characterization, multi‑unit aggregation, information volume) and assesses how ISO/IEC 27005 approaches address them.
  • Risk assessment and treatment
    • Reviews ISO/IEC 27005 processes: context, identification, analysis, evaluation, treatment, communication, monitoring, and review as applied to NPP I&C and EPS.
  • Informative annexes
    • Annex A: national (Chinese) approach summary.
    • Annex B: cyber‑informed engineering considerations for nuclear systems.

Practical applications - who uses IEC TR 63486:2024

  • NPP operators and asset owners - to align plant cybersecurity programs for I&C and EPS with international risk‑management practices.
  • I&C / EPS engineers and system integrators - to evaluate vulnerabilities and integrate risk treatment options compatible with nuclear safety constraints.
  • Cybersecurity practitioners and risk analysts - for mapping ISO/IEC 27005 risk processes to nuclear control environments.
  • Regulators, auditors, and policy makers - to assess operator risk‑management approaches and harmonize regulatory expectations.
  • Vendors and suppliers - to design products and services that meet nuclear cybersecurity program requirements.

Related standards and keywords

  • Related: IEC 62645, IEC 63096, ISO/IEC 27001, ISO/IEC 27005.
  • SEO keywords: IEC TR 63486:2024, nuclear cybersecurity, NPP I&C cybersecurity, EPS cybersecurity, cyber risk management, IEC 62645, ISO/IEC 27005, information security for nuclear facilities.

IEC TR 63486:2024 is a practical reference for aligning nuclear‑grade I&C and EPS cybersecurity risk processes with international ISMS and risk‑assessment best practices.

Buy Documents

Technical report

IEC TR 63486:2024 - Nuclear facilities - Instrumentation, control and electrical power systems - Cybersecurity risk management approaches

ISBN:978-2-8322-9380-5
English language (160 pages)
sale 15% off
Preview
sale 15% off
Preview

Get Certified

Connect with accredited certification bodies for this standard

DNV

DNV is an independent assurance and risk management provider.

NA Norway Verified

Lloyd's Register

Lloyd's Register is a global professional services organisation specialising in engineering and technology.

UKAS United Kingdom Verified

DNV Energy Systems

Energy and renewable energy certification.

NA Norway Verified

Sponsored listings

Frequently Asked Questions

IEC TR 63486:2024 is a technical report published by the International Electrotechnical Commission (IEC). Its full title is "Nuclear facilities - Instrumentation, control and electrical power systems - Cybersecurity risk management approaches". This standard covers: IEC TR 63486:2024 provides a cybersecurity framework for digital I&C programmable systems [2]. IEC 62645 [1] aligns strongly with the information security management system (ISMS) elements detailed within ISO/IEC 27001:2013 [2]. The ISO/IEC ISMS structure corresponds to the “I&C digital programmable system cybersecurity program” in the context (as defined in 5.2.1 of IEC 62645:2019 [1]). The scope of this document is to capture the national and international cyber-risk approaches employed to manage cybersecurity risks associated with Instrumentation and Control (I&C) and Electrical Power Systems (EPS) at a Nuclear Power Plant (NPP). This document summarizes an evaluation of cyber-risk approaches that are in use by nuclear facility operators to manage cybersecurity risks. The scope of this document generally follows the exclusions of IEC 62645 which are: - Non-malevolent actions and events such as accidental failures, human errors (except those stated above, such as impacting the performance of cybersecurity controls), and natural events. In particular, good practices for managing applications and data, including backup and restoration related to accidental failure, are out of scope. This document summarizes key insights of the international and cyber-risk approaches used at NPPs regarding the application of ISO/IEC 27005:2018 [5]. The evaluation is based on 11 challenges to cybersecurity risk management and their applicability to NPP risk management. The challenges are detailed in Clause 7. This document also relates the risk management elements of IEC 62645 and IEC 63096.

IEC TR 63486:2024 provides a cybersecurity framework for digital I&C programmable systems [2]. IEC 62645 [1] aligns strongly with the information security management system (ISMS) elements detailed within ISO/IEC 27001:2013 [2]. The ISO/IEC ISMS structure corresponds to the “I&C digital programmable system cybersecurity program” in the context (as defined in 5.2.1 of IEC 62645:2019 [1]). The scope of this document is to capture the national and international cyber-risk approaches employed to manage cybersecurity risks associated with Instrumentation and Control (I&C) and Electrical Power Systems (EPS) at a Nuclear Power Plant (NPP). This document summarizes an evaluation of cyber-risk approaches that are in use by nuclear facility operators to manage cybersecurity risks. The scope of this document generally follows the exclusions of IEC 62645 which are: - Non-malevolent actions and events such as accidental failures, human errors (except those stated above, such as impacting the performance of cybersecurity controls), and natural events. In particular, good practices for managing applications and data, including backup and restoration related to accidental failure, are out of scope. This document summarizes key insights of the international and cyber-risk approaches used at NPPs regarding the application of ISO/IEC 27005:2018 [5]. The evaluation is based on 11 challenges to cybersecurity risk management and their applicability to NPP risk management. The challenges are detailed in Clause 7. This document also relates the risk management elements of IEC 62645 and IEC 63096.

IEC TR 63486:2024 is classified under the following ICS (International Classification for Standards) categories: 27.100 - Power stations in general; 27.120.20 - Nuclear power plants. Safety. The ICS classification helps identify the subject area and facilitates finding related standards.

IEC TR 63486:2024 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)