BS PD IEC TR 62443-2-3-2015 Security for industrial automation and control systems Patch management in the IACS environment《工业自动化和控制系统的安全性 IACS环境中的补丁管理》.pdf
《BS PD IEC TR 62443-2-3-2015 Security for industrial automation and control systems Patch management in the IACS environment《工业自动化和控制系统的安全性 IACS环境中的补丁管理》.pdf》由会员分享,可在线阅读,更多相关《BS PD IEC TR 62443-2-3-2015 Security for industrial automation and control systems Patch management in the IACS environment《工业自动化和控制系统的安全性 IACS环境中的补丁管理》.pdf(66页珍藏版)》请在麦多课文档分享上搜索。
1、BSI Standards Publication Security for industrial automation and control systems Part 2-3: Patch management in the IACS environment PD IEC/TR 62443-2-3:2015National foreword This Published Document is the UK implementation of IEC/TR 62443-2- 3:2015. The UK participation in its preparation was entrus
2、ted to Technical Committee GEL/65, Measurement and control. A list of organizations represented on this committee can be obtained on request to its secretary. This publication does not purport to include all the necessary provisions of a contract. Users are responsible for its correct application. T
3、he British Standards Institution 2015. Published by BSI Standards Limited 2015 ISBN 978 0 580 83544 5 ICS 25.040.40; 35.040; 35.100 Compliance with a British Standard cannot confer immunity from legal obligations. This Published Document was published under the authority of the Standards Policy and
4、Strategy Committee on 31 July 2015. Amendments/corrigenda issued since publication Date Text affected PUBLISHED DOCUMENT PD IEC/TR 62443-2-3:2015 IEC TR 62443-2-3 Edition 1.0 2015-06 TECHNICAL REPORT Security for industrial automation and control systems Part 2-3: Patch management in the IACS enviro
5、nmentINTERNATIONAL ELECTROTECHNICAL COMMISSION ICS : 25.040.40; 35.040; 35.100 ISBN 978-2-8322-2768-8 Registered trademark of the International Electrotechnical Commission Warning! Make sure that you obtained this publication from an authorized distributor. colour inside PD IEC/TR 62443-2-3:2015 2 I
6、EC TR 62443-2-3:2015 IEC 2015 CONTENTS FOREWORD . 5 INTRODUCTION . 7 1 Scope 8 2 Normative references. 8 3 Terms, definitions, abbreviated terms and acronyms 8 3.1 Terms and definitions 8 3.2 Abbreviated terms and acronyms . 9 4 Industrial automation and control system patching 11 4.1 Patching probl
7、ems faced in industrial automation and control systems . 11 4.2 Impacts of poor patch management . 11 4.3 Obsolete IACS patch management mitigation . 12 4.4 Patch lifecycle state 12 5 Recommended requirements for asset owner . 13 6 Recommended requirements for IACS product supplier 14 7 Exchanging p
8、atch information 14 7.1 General . 14 7.2 Patch information exchange format 15 7.3 Patch compatibility information filename convention . 15 7.4 VPC file schema . 15 7.5 VPC file element definitions . 17 Annex A (informative) VPC XSD file format 21 A.1 VPC XSD file format specification 21 A.2 Core com
9、ponent types 23 A.2.1 Overview . 23 A.2.2 CodeType 23 A.2.3 DateTimeType . 24 A.2.4 IdentifierType . 24 A.2.5 IndicatorType . 25 A.2.6 TextType . 25 Annex B (informative) IACS asset owner guidance on patching . 26 B.1 Annex organization . 26 B.2 Overview. 26 B.3 Information gathering 27 B.3.1 Invent
10、ory of existing environment . 27 B.3.2 Tools for manual and automatic scanning . 29 B.3.3 IACS product supplier contact and relationship building 30 B.3.4 Supportability and product supplier product lifecycle . 32 B.3.5 Evaluation and assessment of existing environment 32 B.3.6 Classification and ca
11、tegorization of assets/hardware/software. 33 B.4 Project planning and implementation . 36 B.4.1 Overview . 36 B.4.2 Developing the business case 37 B.4.3 Establishing and assigning roles and responsibilities 38 B.4.4 Testing environment and infrastructure . 40 B.4.5 Implement backup and restoration
12、infrastructure . 41 B.4.6 Establishing product supplier procurement guidelines . 42 PD IEC/TR 62443-2-3:2015IEC TR 62443-2-3:2015 IEC 2015 3 B.5 Monitoring and evaluation . 42 B.5.1 Overview . 42 B.5.2 Monitoring and identification of security related patches 43 B.5.3 Determining patch applicability
13、 . 43 B.5.4 Impact, criticality and risk assessment 44 B.5.5 Decision for installation 45 B.6 Patch testing . 45 B.6.1 Patch testing process . 45 B.6.2 Asset owner qualification of security patches prior to installation . 46 B.6.3 Determining patch file authenticity 46 B.6.4 Review functional and se
14、curity changes from patches . 46 B.6.5 Installation procedure . 47 B.6.6 Patch qualification and validation . 48 B.6.7 Patch removal, roll back, restoration procedures . 48 B.6.8 Risk mitigation alternatives . 49 B.7 Patch deployment and installation . 50 B.7.1 Patch deployment and installation proc
15、ess . 50 B.7.2 Notification of affected parties 50 B.7.3 Preparation 51 B.7.4 Phased scheduling and installation . 51 B.7.5 Verification of patch installation 52 B.7.6 Staff training and drills . 52 B.8 Operating an IACS patch management program . 53 B.8.1 Overview . 53 B.8.2 Change management . 53
16、B.8.3 Vulnerability awareness . 53 B.8.4 Outage scheduling . 54 B.8.5 Security hardening . 54 B.8.6 Inventory and data maintenance . 54 B.8.7 Procuring or adding new devices 55 B.8.8 Patch management reporting and KPIs . 55 Annex C (informative) IACS product supplier / service provider guidance on p
17、atching . 56 C.1 Annex organization . 56 C.2 Discovery of vulnerabilities 56 C.2.1 General . 56 C.2.2 Vulnerability discovery and identification within the product . 57 C.2.3 Vulnerability discovery and identification within externally sourced product components . 57 C.3 Development, verification an
18、d validation of security updates 58 C.4 Distribution of cyber security updates 58 C.5 Communication and outreach 58 Bibliography . 60 Figure 1 Patch state model 13 Figure 2 VPC file schema . 16 Figure 3 VPC file schema diagram format . 17 Figure B.1 IACS patch management workflow . 27 Figure B.2 Pla
19、nning an IACS patch management process . 36 PD IEC/TR 62443-2-3:2015 4 IEC TR 62443-2-3:2015 IEC 2015 Figure B.3 Sample responsibilities chart . 40 Figure B.4 Patch monitoring and evaluation process . 42 Figure B.5 A patch testing process . 45 Figure B.6 A patch deployment and installation process 5
20、0 Table 1 Patch lifecycle states . 12 Table 2 VPC XSD PatchData file elements . 17 Table 3 VPC XSD PatchVendor file elements . 18 Table 4 VPC XSD Patch file elements 18 Table 5 VPC XSD VendorProduct file elements 20 Table A.1 CodeType optional attributes 24 Table A.2 DateTimeType optional attributes
21、 . 24 Table A.3 IdentifierType optional attributes . 25 Table A.4 IndicatorType optional attributes . 25 Table A.5 TextType optional attributes . 25 Table B.1 Sample product supplier profile. 31 Table B.2 Communication capabilities 34 Table B.3 Sample software categorization 35 Table B.4 Responsibil
22、ity assignment definitions 39 Table B.5 Sample severity based patch management timeframes 45 PD IEC/TR 62443-2-3:2015IEC TR 62443-2-3:2015 IEC 2015 5 INTERNATIONAL ELECTROTECHNICAL COMMISSION _ SECURITY FOR INDUSTRIAL AUTOMATION AND CONTROL SYSTEMS Part 2-3: Patch management in the IACS environment
23、FOREWORD 1) The International Electrotechnical Commission (IEC) is a worldwide organization for standardization comprising all national electrotechnical committees (IEC National Committees). The object of IEC is to promote international co-operation on all questions concerning standardization in the
24、 electrical and electronic fields. To this end and in addition to other activities, IEC publishes International Standards, Technical Specifications, Technical Reports, Publicly Available Specifications (PAS) and Guides (hereafter referred to as “IEC Publication(s)”). Their preparation is entrusted t
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- BSPDIECTR62443232015SECURITYFORINDUSTRIALAUTOMATIONANDCONTROLSYSTEMSPATCHMANAGEMENTINTHEIACSENVIRONMENT

链接地址:http://www.mydoc123.com/p-397706.html