Structure of IEC 62443
IEC 62443 is the international reference standard for Industrial Cyber Security of components and systems developed in conformity with ISA/IEC requirements.
Read moreBYHON is a certification body and laboratory, accredited according to IEC 17065 and IEC 17025, which implements ISASecure® certification processes and provides conformity assessments for Industrial Cyber Security certification as per IEC 62443 with the ISASecure® scheme with license no. ISCI-CL0005.
Combined HMI/PLC systems
SCADA systems
Control system platforms
PCS (Packaged Control Systems)
DCS (Distributed Control Systems)
Safety Instrumented Systems (SIS)
BYHON also offers a conformity assessment inspired by the Industrial Cybersecurity certification schemes according to IEC 62443. In this case, the assessment focuses on the product by verifying its technical compliance with security requirements, whether it is a system or a component.
Watch the video explaining the foundations of ISASecure® certificate.
Defining the scope of assessment in terms of products to be certified, related configurations and security objectives, planning and collecting all relevant documentation, including diagrams related to architecture and information on essential functions, such as a list of accessible network interfaces, protocols and available services.
Where required, verification of the manufacturer's CyberSecurity Management System in order to verify that it has been developed and maintained in accordance with the security practices of IEC 62443-4-1.
The security functionality of the system or component is checked against the requirements defined for each Security Level (SL) to assess whether the object of certification complies with the requirements of the standard according to the product (and therefore with reference to IEC 62443-3-3 for systems or IEC 62443-4-2 for components) and its type (embedded component, networking, etc.) and whether it has been developed as per the life cycle verified in the previous point.
Conducting tests as per the validation plan and product vulnerability analysis. This is done with a vulnerability scan and other tests.
Once all the previous steps have been carried out, the result is recorded in an assessment report for review by BYHON's technical committee. If successful, the final certification of compliance is issued together with the form of an Industrial Cyber Security Certification declaring that the system (or component) complies with IEC 62443 for a given security capability (SL-C).
Industrial Cyber Security is the part of the overall security of an Industrial Automation and Control System (IACS) that depends on the proper security development lifecycle used by product suppliers, where products include DCS and SCADA systems, and components such as embedded devices and software applications.
IEC 62443 is the international standard for the security of industrial automation and control systems. It was developed to protect industry and make data sharing and system operations safe and reliable, reducing the risk of cyber threats, equipment failures, production downtime, unexpected costs, and profit loss.
IACS stands for Industrial Automation Control System, also known as ICS (Industrial Control System). In a broader sense, IACS is synonymous with OT (Operations Technology), as it refers to technology that interfaces with an operational process. Examples of IACS include industrial devices such as PLCs, HMIs, and SCADAs.
The IACS Security Lifecycle is the security lifecycle of an IACS: the set of phases that must be carried out in order for IACS protection to comply with the Cyber Security requirements defined by the IEC standard. The phases of the IACS Security Lifecycle are Assess, Implement, and Maintain.
The CSMS (Cyber Security Management System) represents the set of practices and actions aimed at identifying cyber risks and defining the most appropriate countermeasures.
The Assess Phase consists of a set of activities aimed at identifying high-level risks and analyzing vulnerabilities and low-level risks. It includes Risk Assessment, Vulnerability Assessment, Penetration Test, Threat Modeling, and Security Level Allocation. This phase ends with the allocation of the minimum Cyber Security requirements required for each component of the IACS system.
During the Implement Phase, companies wishing to protect themselves from cyberattacks define the entire CSMS (Cyber Security Management System) and adopt procedures and strategies aimed at preventing cyberattacks and protecting their industrial control systems. Key activities include Defense Strategy, CSMS, and Security Level Verification.
Cyber Security is a process that needs to be constantly monitored and periodically implemented through maintenance activities related to the security level of industrial plants. The Maintain Phase is therefore dedicated to preserving security performance over time and includes activities such as Auditing and Follow up.