ISA TR84 00 09-2013 Security Countermeasures Related to Safety Instrumented Systems (SIS).pdf
《ISA TR84 00 09-2013 Security Countermeasures Related to Safety Instrumented Systems (SIS).pdf》由会员分享,可在线阅读,更多相关《ISA TR84 00 09-2013 Security Countermeasures Related to Safety Instrumented Systems (SIS).pdf(36页珍藏版)》请在麦多课文档分享上搜索。
1、 ISA-TR84.00.09-2013 Security Countermeasures Related to Safety Instrumented Systems (SIS) Approved 6 November 2013 ISA-TR84.00.09-2013 Security Countermeasures Related to Safety Instrumented Systems (SIS) ISBN: 978-0-876640-52-4 Copyright 2013 by ISA. All rights reserved. Not for resale. Printed in
2、 the United States of America. ISA 67 Alexander Drive P. O. Box 12277 Research Triangle Park, NC 27709 USA 3 ISA-TR84.00.09-2013 PREFACE This preface, as well as all footnotes and annexes, is included for information purposes and is not part of ISA-TR84.00.09-2013. This document has been prepared as
3、 part of the service of ISA, the International Society of Automation, toward a goal of uniformity in the field of instrumentation. To be of real value, this document should not be static but should be subject to periodic review. Toward this end, the Society welcomes all comments and criticisms and a
4、sks that they be addressed to the Secretary, Standards and Practices Board; ISA; 67 Alexander Drive; P. O. Box 12277; Research Triangle Park, NC 27709; Telephone (919) 549-8411; Fax (919) 549-8288; E-mail: standardsisa.org. It is the policy of ISA to encourage and welcome the participation of all co
5、ncerned individuals and interests in the development of ISA standards, recommended practices and technical reports. Participation in the ISA standards-making process by an individual in no way constitutes endorsement by the employer of that individual, of ISA or of any of the standards, recommended
6、practices and technical reports that ISA develops. CAUTION ISA DOES NOT TAKE ANY POSITION WITH RESPECT TO THE EXISTENCE OR VALIDITY OF ANY PATENT RIGHTS ASSERTED IN CONNECTION WITH THIS DOCUMENT, AND ISA DISCLAIMS LIABILITY FOR THE INFRINGEMENT OF ANY PATENT RESULTING FROM THE USE OF THIS DOCUMENT.
7、USERS ARE ADVISED THAT DETERMINATION OF THE VALIDITY OF ANY PATENT RIGHTS, AND THE RISK OF INFRINGEMENT OF SUCH RIGHTS, IS ENTIRELY THEIR OWN RESPONSIBILITY. PURSUANT TO ISAS PATENT POLICY, ONE OR MORE PATENT HOLDERS OR PATENT APPLICANTS MAY HAVE DISCLOSED PATENTS THAT COULD BE INFRINGED BY USE OF T
8、HIS DOCUMENT AND EXECUTED A LETTER OF ASSURANCE COMMITTING TO THE GRANTING OF A LICENSE ON A WORLDWIDE, NONDISCRIMINATORY BASIS, WITH A FAIR AND REASONABLE ROYALTY RATE AND FAIR AND REASONABLE TERMS AND CONDITIONS. FOR MORE INFORMATION ON SUCH DISCLOSURES AND LETTERS OF ASSURANCE, CONTACT ISA OR VIS
9、IT WWW.ISA.ORG/STANDARDSPATENTS. OTHER PATENTS OR PATENT CLAIMS MAY EXIST FOR WHICH A DISCLOSURE OR LETTER OF ASSURANCE HAS NOT BEEN RECEIVED. ISA IS NOT RESPONSIBLE FOR IDENTIFYING PATENTS OR PATENT APPLICATIONS FOR WHICH A LICENSE MAY BE REQUIRED, FOR CONDUCTING INQUIRIES INTO THE LEGAL VALIDITY O
10、R SCOPE OF PATENTS, OR DETERMINING WHETHER ANY LICENSING TERMS OR CONDITIONS PROVIDED IN CONNECTION WITH SUBMISSION OF A LETTER OF ASSURANCE, IF ANY, OR IN ANY LICENSING AGREEMENTS ARE REASONABLE OR NON-DISCRIMINATORY. ISA REQUESTS THAT ANYONE REVIEWING THIS DOCUMENT WHO IS AWARE OF ANY PATENTS THAT
11、 MAY IMPACT IMPLEMENTATION OF THE DOCUMENT NOTIFY THE ISA STANDARDS AND PRACTICES DEPARTMENT OF THE PATENT AND ITS OWNER. ADDITIONALLY, THE USE OF THIS DOCUMENT MAY INVOLVE HAZARDOUS MATERIALS, OPERATIONS OR PROCESS EQUIPMENT. THE DOCUMENT CANNOT ANTICIPATE ALL POSSIBLE APPLICATIONS OR ADDRESS ALL P
12、OSSIBLE SAFETY ISSUES ASSOCIATED WITH USE IN HAZARDOUS CONDITIONS. THE USER OF THIS TECHNICAL REPORT SHOULD EXERCISE SOUND PROFESSIONAL JUDGMENT CONCERNING ITS USE AND APPLICABILITY UNDER THE USERS PARTICULAR CIRCUMSTANCES. THE USER SHOULD ALSO CONSIDER THE APPLICABILITY OF ANY GOVERNMENTAL REGULATO
13、RY LIMITATIONS AND ESTABLISHED SAFETY AND HEALTH PRACTICES BEFORE IMPLEMENTING THIS DOCUMENT. ISA-TR84.00.09-2013 4 The following members of ISA84 Working Group 9 served as active contributors in the development of this technical report: NAME AFFILIATION Harold W Thomas, Working Group Chair exida Ma
14、rc Baque Total Keith Bellville Emerson Michael Corbo ExxonMobil John Cusimano exida Ed Crawford Chevron James Gilsinn Kenexis William Hearn SIS-Tech Kevin Klein Chevron Joel Langill Scadahacker Vic Maggioli Feltronics This technical report was approved for publication by the ISA Standards and Practi
15、ces Board on 6 November 2013. NAME AFFILIATION E. Cosman, Vice President The Dow Chemical Company D. Bartusiak ExxonMobil Chemical Company P. Brett Honeywell Inc. J. Campbell Consultant M. Coppler Det Norske Veritas Certification Inc. B. Dumortier Schneider Electric D. Dunn Aramco Services Co. J. Fe
16、derlein Federlein Inventory (including subsystems, network devices, software); Definition of roles and responsibilities; Cybersecurity risk assessment; Security of operation (including the network segregation re: Annex A, the logical and physical protection); Maintenance policy and contract manageme
17、nt; Maintenance tools; 13 ISA-TR84.00.09-2013 Incident response and disaster recovery plan; Backup and host protection (for example, antivirus, application white listing) management; Patch upgrade management; Confidentiality of its work by limiting the communication of the specific practices employe
18、d to meet the objectives of cybersecurity. Only specific personnel within the organization with the need to fully understand the tactics employed should receive this communication. The organization responsible for security should also be engaged during each phase of the safety life cycle. This helps
19、 to maintain communication between the organizations and assess potential consequences within each groups existing scope to ensure that each areas initiatives complement the others. Persons, departments or organizations involved in cybersecurity life-cycle activities should be competent to carry out
20、 the activities for which they are accountable. As skill requirements change due to new equipment or procedures, senior technical and management personnel should review competency requirements to ensure the desired outcome for their facilitys SIS installations. 5 Hazard and risk analysis (Clause 8)
21、The hazards of significance to a SIS relative to security protection include: Safety instrumented function (SIF) failure to function when needed; SIF spuriously functions; and Common mode failure of basic process control system (BPCS) generating a demand with the SIS in a fail-to-function state. A r
22、isk assessment should be performed that concentrates on the potential likelihood and consequences of an event occurring. This risk assessment should contain aspects of both safety and security and reflect the possible consequences of a failure to provide adequate security countermeasures. Safety ris
23、k assessments are, in general, much more quantitative in nature than those for security due to the different potential threat sources. The security threat landscape is constantly changing, but there are some general classifications of potential threats as described in the ISA/IEC 62443 series that a
24、n organization should consider: Malicious hacker an individual whose objective is to penetrate the security defenses of a third-party computer system or network. (ISO/IEC 27002 - see Bibliography) Professional hackers an organization funded by a government or other entity specifically aimed at penet
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ISATR8400092013SECURITYCOUNTERMEASURESRELATEDTOSAFETYINSTRUMENTEDSYSTEMSSISPDF

链接地址:http://www.mydoc123.com/p-789997.html