ISA 62443-4-1-2018 Security for industrial automation and control systems Part 4-1 Product security development life-cycle requirements.pdf
《ISA 62443-4-1-2018 Security for industrial automation and control systems Part 4-1 Product security development life-cycle requirements.pdf》由会员分享,可在线阅读,更多相关《ISA 62443-4-1-2018 Security for industrial automation and control systems Part 4-1 Product security development life-cycle requirements.pdf(66页珍藏版)》请在麦多课文档分享上搜索。
1、 NOTICE OF COPYRIGHT This is a copyright document and may not be copied or distributed in any form or manner without the permission of ISA. This copy of the document was made for the sole use of the person to whom ISA provided it and is subject to the restrictions stated in ISAs license to that pers
2、on. It may not be provided to any other person in print, electronic, or any other form. Violations of ISAs copyright will be prosecuted to the fullest extent of the law and may result in substantial civil and criminal penalties. AMERICAN NATIONAL STANDARD ANSI/ISA-62443-4-1-2018 Security for industr
3、ial automation and control systems Part 4-1: Product security development life-cycle requirements Approved 16 February 2018 ANSI/ISA-62443-4-1-2018 Security for industrial automation and control systems Part 4-1: Product security development life-cycle requirements ISBN: 978-1-945541-82-7 Copyright
4、2018 by ISA. All rights reserved. Not for resale. Printed in the United States of America. ISA 67 T.W. Alexander Drive P. O. Box 12277 Research Triangle Park, NC 27709 USA 16 February 2018 3 ANSI/ISA-62443-4-1-2018 Preface This preface, as well as all footnotes and annexes, is included for informati
5、on purposes and is not part of ANSI/ISA-62443-4-1-2018. This document has been prepared as part of the service of ISA, the International Society for Automation, toward a goal of uniformity in the field of instrumentation. To be of real value, this document should not be static but should be subject
6、to periodic review. Toward this end, the Society welcomes all comments and criticisms and asks that they be addressed to the Secretary, Standards and Practices Board; ISA; 67 T.W. Alexander Drive; P. O. Box 12277; Research Triangle Park, NC 27709; Telephone (919) 549-8411; Fax (919) 549-8288; E-mail
7、: standardsisa.org. The ISA Standards and Practices Department is aware of the growing need for attention to the metric system of units in general, and the International System of Units (SI) in particular, in the preparation of instrumentation standards. The Department is further aware of the benefi
8、ts to U SA users of ISA standards of incorporating suitable references to the SI (and the metric system) in their business and professional dealings with other countries. Toward this end, this Department will endeavor to introduce SI-acceptable metric units in all new and revised standards, recommen
9、ded practices, and technical reports to the greatest extent possible. Standard for Use of the International System of Units (SI): The Modern Metric System, published by the American Society for Testing certifies industry professionals; provides education and training; publishes books and technical a
10、rticles; hosts conferences and exhibits; and provides networking and career development programs for its 40,000 members and 400,000 customers around the world. ISA owns A, a leading online publisher of automation-related content, and is the founding sponsor of The Automation Federation (www.automati
11、onfederation.org), an association of non-profit organizations serving as “The Voice of Automation.“ Through a wholly owned subsidiary, ISA bridges the gap between standards and their implementation with the ISA Security Compliance Institute (www.isasecure.org) and the ISA Wireless Compliance Institu
12、te (www.isa100wci.org). 16 February 2018 5 ANSI/ISA-62443-4-1-2018 The following people served as active members of ISA99 Working Group 04, Task Group 06 in the preparation of this document: Name Company Contributor Reviewer Johan Nye, WG Chair Exxon X Kevin Staggs, WG Chair Honeywell X Michael Medo
13、ff, TG Lead Exida X X Mike Ahmadi Codenomicon, Ltd. X X Shameem Akhter Intel Corporation X X Andreas Backman ABB X X Satish Balasubramanian Yokogawa IA Technologies X X Eric Braun Emerson Process Management X X Fabio Buhrer ABB X Eric Cosman OIT Concepts LLC X Ed Crawford Chevron X John Cusimano AE
14、Solutions X X Emmanuel DelaHostria Consultant X John Feikis Dell X Paul Forney Schneider Electric X X Ken Frische AE Solutions X Dennis Holstein OPUS Consulting Group X Charles Hoover SmartWorks X Dave Johnson Exida X X Pierre Kobes Siemens X John Lellis Berkana Resources Corporation X Mike Lester E
15、merson Process Management X Suzanne Lightman NIST X Roberto Minicucci GE Oil Open Web Application Security Project (OWASP) Comprehensive, Lightweight Application Security Process (CLASP) 35; The Security Development Life-cycle by Michael Howard and Steve Lipner 45; IEC 61508 Functional safety of ele
16、ctrical/electronic/programmable electronic safety-related systems 22, and RCTA DO-178B Software Considerations in Airborne Systems and Equipment Certification 27. Therefore, all these sources can be considered contributing sources to this standard. This document is the part of the ISA-62443 series t
17、hat contains security requirements for developers of any automation and control products where security is a concern. Figure 1 illustrates the relationship of the different parts of ISA-62443 that were in existence or planned as of the date of circulation of this document. Those that are normatively
18、 referenced are included in the list of normative references in Clause 2, and those that are referenced for informational purposes or that are in development are listed in the Bibliography. ANSI/ISA-62443-4-1-2018 16 16 February 2018 Figure 1 Parts of the ISA-62443 series Figure 2 Example scope of p
19、roduct life-cycle illustrates how the developed product relates to maintenance and integration capabilities defined in IEC 6244324 5 and to its operation by the asset owner. The product supplier develops products using a process compliant with this standard. Those products may be a single component,
20、 such as an embedded controller, or a group of components working together as a system or subsystem. The products are then integrated together, usually by a system integrator, into an Automation Solution using a process compliant with IEC 6244324. The Automation Solution is then installed at a parti
21、cular site and becomes part of the industrial automation and control system (IACS). Some of these capabilities reference security measures defined in ANSI/ISA-624433 3 (99.03.03) 8 that the service provider ensures are supported in the Automation Solution (either as product features or compensating
22、mechanisms). This standard only addresses the process used for the development of the product; it does not address design, installation or operation of the Automation Solution or IACS. In Figure 2, the Automation Solution is illustrated to contain one or more subsystems and optional supporting compo
23、nents such as advanced control. The dashed boxes indicate that these components are “optional”. NOTE 1 Automation Solutions typically have a single product, but they are not restricted to do so. In some industries, there may be a hierarchical product structure. In general, the Automation Solution is
24、 the set of hardware and software, independent of product packaging, that is used to control a physical process (for example, continuous or manufacturing) as defined by the asset owner. NOTE 2 If a service provider provides products used in the Automation Solution, then the service provider is fulfi
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ISA62443412018SECURITYFORINDUSTRIALAUTOMATIONANDCONTROLSYSTEMSPART41PRODUCTSECURITYDEVELOPMENTLIFECYCLEREQUIREMENTSPDF

链接地址:http://www.mydoc123.com/p-789742.html