BS DD IEC PAS 62443-3-2008 Security for industrial process measurement and control - Network and system security《工业过程的测量和控制安全 网络和系统安全》.pdf
《BS DD IEC PAS 62443-3-2008 Security for industrial process measurement and control - Network and system security《工业过程的测量和控制安全 网络和系统安全》.pdf》由会员分享,可在线阅读,更多相关《BS DD IEC PAS 62443-3-2008 Security for industrial process measurement and control - Network and system security《工业过程的测量和控制安全 网络和系统安全》.pdf(56页珍藏版)》请在麦多课文档分享上搜索。
1、DRAFT FOR DEVELOPMENTDD IEC/PAS 62443-3:2008Security for industrial process measurement and control Part 3: Network and system securityICS 25.040.40; 35.040; 35.110g49g50g3g38g50g51g60g44g49g42g3g58g44g55g43g50g56g55g3g37g54g44g3g51g40g53g48g44g54g54g44g50g49g3g40g59g38g40g51g55g3g36g54g3g51g40g53g4
2、8g44g55g55g40g39g3g37g60g3g38g50g51g60g53g44g42g43g55g3g47g36g58DD IEC/PAS 62443-3:2008This Draft for Development was published under the authority of the Standards Policy and Strategy Committee on 29 August 2008 BSI 2008ISBN 978 0 580 62208 3National forewordThis Draft for Development is the UK imp
3、lementation of IEC/PAS 62443-3:2008.This publication is not to be regarded as a British Standard.It is being issued in the Draft for Development series of publications and is of a provisional nature. It should be applied on this provisional basis, so that information and experience of its practical
4、application can be obtained.A PAS is a Technical Specification not fulfilling the requirements for a standard, but made available to the public and established in an organization operating under a given procedure.A review of this Draft for Development will be carried out not later than three years a
5、fter its publication.Notification of the start of the review period, with a request for the submission of comments from users of this Draft for Development, will be made in an announcement in the appropriate issue of Update Standards. According to the replies received, the responsible BSI Committee
6、will judge whether the validity of the PAS should be extended for a further three years or what other action should be taken and pass their comments on to the relevant international committee.Observations which it is felt should receive attention before the official call for comments will be welcome
7、d. These should be sent to the Secretary of the responsible BSI Technical Committee at British Standards House, 389 Chiswick High Road, London W4 4AL.The UK participation in its preparation was entrusted to Technical Committee AMT/7, Industrial communications: process measurement and control, includ
8、ing fieldbus.A list of organizations represented on this committee can be obtained on request to its secretary.This publication does not purport to include all the necessary provisions of a contract. Users are responsible for its correct application.Amendments/corrigenda issued since publicationDate
9、 CommentsIEC/PAS 62443-3Edition 1.0 2008-01PUBLICLY AVAILABLE SPECIFICATIONPRE-STANDARD Security for industrial process measurement and control Network and system security DD IEC/PAS 62443-3:2008CONTENTS INTRODUCTION.3 1 Scope.4 2 Normative references .4 3 Terms, definitions, symbols, abbreviated te
10、rms and conventions 5 3.1 Terms and definitions 5 3.2 Symbols and abbreviated terms.11 4 Introduction and compliance.12 5 Principles and reference models.12 5.1 General .12 5.2 Threat-risk model 13 5.3 Security life cycle 15 5.4 Policy 16 5.5 Generic reference configurations.19 5.6 Protection models
11、 .22 6 ICS security policy Overview .27 7 ICS security policy Principles and assumptions .29 7.1 ICS security policy Principles .29 7.2 ICS security policy Assumptions and exclusions.30 7.3 ICS security policy Organization and management. 32 8 ICS security policy Measures.36 8.1 Availability managem
12、ent36 8.2 Integrity management38 8.3 Logical access management .41 8.4 Physical access management44 8.5 Partition management .45 8.6 External access management46 Annex A Projected new edition of IEC 62443 50 Bibliography52 Figure 1 Threat-risk relationship 13 Figure 2 Security life cycle.15 Figure 3
13、 Policy levels.17 Figure 4 Industrial control system (ICS) .20 Figure 5 GPH reference configuration: Generic ICS host with external devices 21 Figure 6 Device protection: Hardening and access management22 Figure 7 Defense-in-depth through partitioning 24 Figure 8 Example: ICS partitioning.25 Figure
14、9 Generic external connectivity .26 DD IEC/PAS 62443-3:2008 2 INTRODUCTION The increasing degree of public networking of formerly isolated automation systems increases the exposure of such systems to attack. Standard IT security protection mechanisms have protection goals and strategies that may be
15、inappropriate for automation systems. This PAS addresses the topic of securing access to and within industrial systems while assuring timely response which may be critical to plant operation. For safety applications and applications in the pharmaceutical or other highly specialized industries, addit
16、ional standards, guidelines, definitions and stipulations may apply, for example, IEC 61508, GAMP (ISPE), for GMP Compliance 21 CFR (FDA) and the Standard Operating Procedure of the European Medicines Agency (SOP/INSP/2003). DD IEC/PAS 62443-3:2008 3 SECURITY FOR INDUSTRIAL PROCESS MEASUREMENT AND C
17、ONTROL NETWORK AND SYSTEM SECURITY 1 Scope This PAS establishes a framework for securing information and communication technology aspects of industrial process measurement and control systems including its networks and devices on those networks, during the operational phase of the plants life cycle.
18、 This PAS provides guidance on a plants operational security requirements and is primarily intended for automation system owners/operators (responsible for ICS operation) Furthermore, the operational requirements of this PAS may interest ICS stakeholders such as: a) automation system designers; b) m
19、anufacturers (vendors) of devices, subsystems, and systems; c) integrators of subsystems and systems. The PAS allows for the following concerns: graceful migration/evolution of existing systems; meeting security objectives with existing COTS technologies and products; assurance of reliability/availa
20、bility of the secured communications services; applicability to systems of any size and risk (scalability); coexistence of safety, legal and regulatory and automation functionality requirements with security requirements. NOTE 1 Plants and systems may contain safety critical components and devices.
21、Any safety-related security components may be subject to certification based on IEC 61508 and according to the SILs therein. This PAS does not guarantee that its specifications are all or in part appropriate or sufficient for the security of such safety critical components and devices. NOTE 2 This P
22、AS does not include requirements for security assurance evaluation and testing. NOTE 3 The measures provided by this PAS are rather process-based and general in nature than technically specific or prescriptive in terms of technical countermeasures and configurations. NOTE 4 The procedures of this PA
23、S are written with the plant owner/operators mind set. NOTE 5 This PAS does not cover the concept, design and implementation live cycle processes, i.e. requirements on control equipment manufacturers future product development cycle. NOTE 6 This PAS does not cover the integration of components and s
24、ubsystems into a system. NOTE 7 This PAS does not cover procurement for integration into an existing system, i.e. procurement requirements for owner/operators of a plant. NOTE 8 This PAS will be extended into a 3-part International Standard to cover most of the restrictions expressed in the previous
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- BSDDIECPAS6244332008SECURITYFORINDUSTRIALPROCESSMEASUREMENTANDCONTROLNETWORKANDSYSTEMSECURITY 工业 过程 测量

链接地址:http://www.mydoc123.com/p-548300.html