IEC TS 62443-1-1-2009 Industrial communication networks - Network and system security - Part 1 Terminology concepts and models《工业通信网络.网络和系统安全.第1部分 术语 概念和模型》.pdf
《IEC TS 62443-1-1-2009 Industrial communication networks - Network and system security - Part 1 Terminology concepts and models《工业通信网络.网络和系统安全.第1部分 术语 概念和模型》.pdf》由会员分享,可在线阅读,更多相关《IEC TS 62443-1-1-2009 Industrial communication networks - Network and system security - Part 1 Terminology concepts and models《工业通信网络.网络和系统安全.第1部分 术语 概念和模型》.pdf(86页珍藏版)》请在麦多课文档分享上搜索。
1、 IEC/TS 62443-1-1 Edition 1.0 2009-07 TECHNICAL SPECIFICATIONIndustrial communication networks Network and system security Part 1-1: Terminology, concepts and models IEC/TS 62443-1-1:2009(E) colour inside THIS PUBLICATION IS COPYRIGHT PROTECTED Copyright 2009 IEC, Geneva, Switzerland All rights rese
2、rved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from either IEC or IECs member National Committee in the country of the requester. If
3、 you have any questions about IEC copyright or have an enquiry about obtaining additional rights to this publication, please contact the address below or your local IEC member National Committee for further information. Droits de reproduction rservs. Sauf indication contraire, aucune partie de cette
4、 publication ne peut tre reproduite ni utilise sous quelque forme que ce soit et par aucun procd, lectronique ou mcanique, y compris la photocopie et les microfilms, sans laccord crit de la CEI ou du Comit national de la CEI du pays du demandeur. Si vous avez des questions sur le copyright de la CEI
5、 ou si vous dsirez obtenir des droits supplmentaires sur cette publication, utilisez les coordonnes ci-aprs ou contactez le Comit national de la CEI de votre pays de rsidence. IEC Central Office 3, rue de Varemb CH-1211 Geneva 20 Switzerland Email: 0Hinmailiec.ch Web: 1Hwww.iec.ch About IEC publicat
6、ions The technical content of IEC publications is kept under constant review by the IEC. Please make sure that you have the latest edition, a corrigenda or an amendment might have been published. Catalogue of IEC publications: 2Hwww.iec.ch/searchpub The IEC on-line Catalogue enables you to search by
7、 a variety of criteria (reference number, text, technical committee,). It also gives information on projects, withdrawn and replaced publications. IEC Just Published: 3Hwww.iec.ch/online_news/justpub Stay up to date on all new IEC publications. Just Published details twice a month all new publicatio
8、ns released. Available on-line and also by email. Electropedia: 4Hwww.electropedia.org The worlds leading online dictionary of electronic and electrical terms containing more than 20 000 terms and definitions in English and French, with equivalent terms in additional languages. Also known as the Int
9、ernational Electrotechnical Vocabulary online. Customer Service Centre: 5Hwww.iec.ch/webstore/custserv If you wish to give us your feedback on this publication or need further assistance, please visit the Customer Service Centre FAQ or contact us: Email: 6Hcsciec.ch Tel.: +41 22 919 02 11 Fax: +41 2
10、2 919 03 00 IEC/TS 62443-1-1 Edition 1.0 2009-07 TECHNICAL SPECIFICATIONIndustrial communication networks Network and system security Part 1-1: Terminology, concepts and models INTERNATIONAL ELECTROTECHNICAL COMMISSION XC ICS 25.040.40; 33.040.040; 35.040 PRICE CODE ISBN 2-8318-1053-6 Registered tra
11、demark of the International Electrotechnical Commission colour inside 2 TS 62443-1-1 IEC:2009(E) CONTENTS FOREWORD.5 INTRODUCTION.7 1 Scope.8 1.1 General .8 1.2 Included functionality .8 1.3 Systems and interfaces8 1.4 Activity-based criteria 9 1.5 Asset-based criteria.9 2 Normative references10 3 T
12、erms, definitions and abbreviations.10 3.1 General .10 3.2 Terms and definitions 10 3.3 Abbreviations.26 4 The situation.27 4.1 General .27 4.2 Current systems 27 4.3 Current trends .28 4.4 Potential impact.28 5 Concepts 29 5.1 General .29 5.2 Security objectives.29 5.3 Foundational requirements 30
13、5.4 Defence in depth .30 5.5 Security context.30 5.6 Threat-risk assessment .32 5.6.1 General .32 5.6.2 Assets .32 5.6.3 Vulnerabilities 34 5.6.4 Risk.34 5.6.5 Threats36 5.6.6 Countermeasures 38 5.7 Security program maturity39 5.7.1 Overview .39 5.7.2 Maturity phases .42 5.8 Policies .45 5.8.1 Overv
14、iew .45 5.8.2 Enterprise level policy46 5.8.3 Operational policies and procedures 47 5.8.4 Topics covered by policies and procedures 47 5.9 Security zones.50 5.9.1 General .50 5.9.2 Determining requirements50 5.10 Conduits51 5.10.1 General .51 5.10.2 Channels .52 5.11 Security levels .53 TS 62443-1-
15、1 IEC:2009(E) 3 5.11.1 General .53 5.11.2 Types of security levels53 5.11.3 Factors influencing SL(achieved) of a zone or conduit 55 5.11.4 Impact of countermeasures and inherent security properties of devices and systems57 5.12 Security level lifecycle57 5.12.1 General .57 5.12.2 Assess phase 58 5.
16、12.3 Develop and implement phase .59 5.12.4 Maintain phase 60 6 Models .61 6.1 General .61 6.2 Reference models .62 6.2.1 Overview .62 6.2.2 Reference model levels63 6.3 Asset models.65 6.3.1 Overview .65 6.3.2 Enterprise68 6.3.3 Geographic sites68 6.3.4 Area 68 6.3.5 Lines, units, cells, vehicles.6
17、8 6.3.6 Supervisory control equipment .68 6.3.7 Control equipment .68 6.3.8 Field I/O network .69 6.3.9 Sensors and actuators .69 6.3.10 Equipment under control 69 6.4 Reference architecture 69 6.5 Zone and conduit model.69 6.5.1 General .69 6.5.2 Defining security zones 70 6.5.3 Zone identification
18、 .70 6.5.4 Zone characteristics.74 6.5.5 Defining conduits .76 6.5.6 Conduit characteristics.77 6.6 Model relationships79 Bibliography81 Figure 1 Comparison of objectives between IACS and general IT systems 29 Figure 2 Context element relationships.31 Figure 3 Context model 31 Figure 4 Integration o
19、f business and IACS cybersecurity.40 Figure 5 Cybersecurity level over time 40 Figure 6 Integration of resources to develop the CSMS.41 Figure 7 Conduit example.52 Figure 8 Security level lifecycle.58 Figure 9 Security level lifecycle Assess phase .59 Figure 10 Security level lifecycle Implement pha
20、se 60 Figure 11 Security level lifecycle Maintain phase61 4 TS 62443-1-1 IEC:2009(E) Figure 12 Reference model for IEC 62443 standards 62 Figure 13 SCADA reference model.63 Figure 14 Process manufacturing asset model example66 Figure 15 SCADA system asset model example67 Figure 16 Reference architec
21、ture example69 Figure 17 Multiplant zone example .71 Figure 18 Separate zones example.72 Figure 19 SCADA zone example.73 Figure 20 SCADA separate zones example.74 Figure 21 Enterprise conduit.77 Figure 22 SCADA conduit example.78 Figure 23 Model relationships.80 Table 1 Types of loss by asset type33
22、 Table 2 Security maturity phases43 Table 3 Concept phase 43 Table 4 Functional analysis phase43 Table 5 Implementation phase44 Table 6 Operations phase 44 Table 7 Recycle and disposal phase.45 Table 8 Security levels .53 TS 62443-1-1 IEC:2009(E) 5 INTERNATIONAL ELECTROTECHNICAL COMMISSION _ INDUSTR
23、IAL COMMUNICATION NETWORKS NETWORK AND SYSTEM SECURITY Part 1-1: Terminology, concepts and models FOREWORD 1) The International Electrotechnical Commission (IEC) is a worldwide organization for standardization comprising all national electrotechnical committees (IEC National Committees). The object
24、of IEC is to promote international co-operation on all questions concerning standardization in the electrical and electronic fields. To this end and in addition to other activities, IEC publishes International Standards, Technical Specifications, Technical Reports, Publicly Available Specifications
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- IECTS62443112009INDUSTRIALCOMMUNICATIONNETWORKSNETWORKANDSYSTEMSECURITYPART1TERMINOLOGYCONCEPTSANDMODELS

链接地址:http://www.mydoc123.com/p-1238281.html