Structure of IEC 62443
IEC 62443 is the international reference standard for Industrial Cyber Security of components and systems developed in conformity with ISA/IEC requirements.
Read moreThe assessment provides evidence of the compliance of specific installations with the requirements of the IEC 62443 standard to verify the achievement of a specific security level (SL-A).
Recently, ISA has made available the ACCSA certification scheme, dedicated to automation solutions installed within production facilities. Since this type of certification is still in the experimental phase, BYHON has implemented in its model a conformity assessment inspired by the Industrial Cybersecurity certification schemes according to IEC 62443, aimed at verifying final OT configurations.
Watch the video explaining the foundations of ISASecure® certificate.
Defining the scope of assessment in terms of configurations and security objectives, planning and collecting all relevant documentation, including diagrams related to architecture and information on essential functions, such as a list of accessible network interfaces, protocols and available services. Analysis of the specific configurations of the various parts of the automation solution.
Where required, verification of the manufacturer’s CyberSecurity Management System in order to verify that it has been developed and maintained in accordance with the security practices of IEC 62443-4-1.
Security features are checked against the requirements defined for a given Security Level target (SL-T) for the different zones and conduits that make up the automation solution, to assess whether the object of assessment complies with the requirements of IEC 62443-3-3 as designed, configured and installed.
Conducting tests as per the validation plan and product vulnerability analysis. This is done with a vulnerability scan and other tests.
Once all the previous steps have been carried out, the result is recorded in an industrial information security assessment report for review by BYHON’s technical committee. If successful, the final Declaration of Conformity is issued to certify that the final configuration of the automation solution conforms to IEC 62443 for a given security level (SL-A).
Industrial Cyber Security is the part of the overall security of an Industrial Automation and Control System (IACS) that depends on the proper security development lifecycle used by product suppliers, where products include DCS and SCADA systems, and components such as embedded devices and software applications.
IEC 62443 is the international standard for the security of industrial automation and control systems. It was developed to protect industry and make data sharing and system operations safe and reliable, reducing the risk of cyber threats, equipment failures, production downtime, unexpected costs, and profit loss.
IACS stands for Industrial Automation Control System, also known as ICS (Industrial Control System). In a broader sense, IACS is synonymous with OT (Operations Technology), as it refers to technology that interfaces with an operational process. Examples of IACS include industrial devices such as PLCs, HMIs, and SCADAs.
The IACS Security Lifecycle is the security lifecycle of an IACS: the set of phases that must be carried out in order for IACS protection to comply with the Cyber Security requirements defined by the IEC standard. The phases of the IACS Security Lifecycle are Assess, Implement, and Maintain.
The CSMS (Cyber Security Management System) represents the set of practices and actions aimed at identifying cyber risks and defining the most appropriate countermeasures.
The Assess Phase consists of a set of activities aimed at identifying high-level risks and analyzing vulnerabilities and low-level risks. It includes Risk Assessment, Vulnerability Assessment, Penetration Test, Threat Modeling, and Security Level Allocation. This phase ends with the allocation of the minimum Cyber Security requirements required for each component of the IACS system.
During the Implement Phase, companies wishing to protect themselves from cyberattacks define the entire CSMS (Cyber Security Management System) and adopt procedures and strategies aimed at preventing cyberattacks and protecting their industrial control systems. Key activities include Defense Strategy, CSMS, and Security Level Verification.
Cyber Security is a process that needs to be constantly monitored and periodically implemented through maintenance activities related to the security level of industrial plants. The Maintain Phase is therefore dedicated to preserving security performance over time and includes activities such as Auditing and Follow up.