IEC 62443-2-4 Ed. 2.0 b:2023 PDF

IEC 62443-2-4 Ed. 2.0 b:2023 PDF

Name:
IEC 62443-2-4 Ed. 2.0 b:2023 PDF

Published Date:
12/01/2023

Status:
Active

Description:

Security for industrial automation and control systems - Part 2-4: Security program requirements for IACS service providers

Publisher:
International Electrotechnical Commission

Document status:
Active

Format:
Electronic (PDF)

Delivery time:
10 minutes

Delivery time (for Russian version):
200 business days

SKU:

Choose Document Language:
$136.5
Need Help?

This part of IEC 62443 specifies a comprehensive set of requirements for security-related processes that IACS service providers can offer to the asset owner during integration and maintenance activities of an Automation Solution. Because not all requirements apply to all industry groups and organizations, Subclause 4.1.4 provides for the development of "profiles" that allow for the subsetting of these requirements. Profiles are used to adapt this document to specific environments, including environments not based on an IACS.

NOTE 1 The term "Automation Solution" is used as a proper noun (and therefore capitalized) in this document to prevent confusion with other uses of this term.

Collectively, the security processes offered by an IACS service provider are referred to as its Security Program (SP) for IACS asset owners. In a related specification, IEC 62443-2-1 describes requirements for the Security Management System of the asset owner.

NOTE 2 In general, these security capabilities are policy, procedure, practice and personnel related. 

Figure 1 illustrates the integration and maintenance security processes of the asset owner, service provider(s), and product supplier(s) of an IACS and their relationships to each other and to the Automation Solution. Some of the requirements of this document relating to the safety program are associated with security requirements described in IEC 62443-3-3 and IEC 62443-4-2.

NOTE 3 The IACS is a combination of the Automation Solution and the organizational measures necessary for its design, deployment, operation, and maintenance.

NOTE 4 Maintenance of legacy system with insufficient security technical capabilities, implementation of policies, processes and procedures can be addressed through risk mitigation.


Figure 1 – Scope of service provider processes
In Figure 1, the Automation Solution is illustrated to contain essential functions that include safety functions, commonly implemented by a Safety Instrumented System (SIS), and complementary and control functions, commonly implemented by supporting applications, such as batch management, advanced control, historian, and security related applications. The dashed boxes identify organizational roles that perform the indicated actions.

NOTE 5 Automation Solutions typically have a single control system (product), but they are not restricted to do so. In general, the Automation Solution is the set of hardware and software, independent of product packaging, which is used to control a physical process (e.g. continuous or manufacturing) as defined by the asset owner.

NOTE 6 Service providers often provide generic architectures that can be adapted for integration into an Automation Solution. These generic architectures are often referred to as "reference architectures".


Edition : 2.0
File Size : 1 file , 1.9 MB
ISBN(s) : 9782832277799
Published : 12/01/2023

History

IEC 62443-2-4 Ed. 2.0 b:2023
Published Date: 12/01/2023
Security for industrial automation and control systems - Part 2-4: Security program requirements for IACS service providers
$136.5
IEC 62443-2-4 Ed. 1.1 b:2017
Published Date: 08/24/2017
Security for industrial automation and control systems - Part 2-4: Security program requirements for IACS service providers CONSOLIDATED EDITION
$208.8
IEC 62443-2-4 Ed. 1.1 en:2017
Published Date: 08/24/2017
Security for industrial automation and control systems - Part 2-4: Security program requirements for IACS service providers CONSOLIDATED EDITION
$151.8

Related products

IEC 62541-4 Ed. 3.0 b:2020
Published Date: 07/13/2020
OPC Unified Architecture - Part 4: Services
$153.6
IEC 62439-4 Ed. 1.0 b:2010
Published Date: 02/26/2010
Industrial communication networks - High availability automation networks - Part 4: Cross-network Redundancy Protocol (CRP)
$98.7
IEC 61158-3-2 Ed. 3.0 b:2023
Published Date: 03/01/2023
Industrial communication networks - Fieldbus specifications - Part 3 - 2: Data-link layer service definition - Type 2 elements
$98.7

Best-Selling Products