New ISA/IEC Standard Specifies Cybersecurity Capabilities for Control System Components

ISA

 

October 4, 2018

The ISA/IEC 62443 series of standards, developed by the ISA99 committee as American National Standards and adopted globally by the International Electrotechnical Commission (IEC), is designed to provide a flexible framework to address and mitigate current and future security vulnerabilities in industrial automation and control systems (IACS).

A newly published standard in the series, ISA/IEC 62443-4-2-2018, Security for Industrial Automation and Control Systems: Technical Security Requirements for IACS Components, provides the cybersecurity technical requirements for components that make up an IACS, specifically the embedded devices, network components, host components and software applications. The standard sets forth security capabilities that enable a component to mitigate threats for a given security level without the assistance of compensating countermeasures.

“The standard definition of the security capabilities for system components provides a common language for product suppliers and all other control system stakeholders,” emphasizes Kevin Staggs of Honeywell, who led the ISA99 development group for the standard. “This simplifies the procurement and integration processes for the computers, applications, network equipment and control devices that make up a control system.”

The new standard follows the February 2018 publication of ISA/IEC 62443-4-1, Product Security Development Life-Cycle Requirements, which specifies process requirements for the secure development of products used in an IACS and defines a secure development life-cycle for developing and maintaining secure products. The life-cycle includes security requirements definition, secure design, secure implementation (including coding guidelines), verification and validation, defect management, patch management and product end-of-life.

The ISA99 standards committee draws on the input and knowledge of IACS security experts from across the globe to develop consensus standards that are applicable to all industry sectors and critical infrastructure. Previous documents in the ISA/IEC 62443 series cover terminology, concepts, and models; establishment of an IACS security program; patch management; and system security requirements and security levels. All may be accessed at www.isa.org/findstandards.

For more information www.isa.org

 

 

 

Related Articles


Changing Scene

  • Spartan Controls Partners with Northwestern Polytechnic to Empower the Next Generation of Engineers

    Spartan Controls Partners with Northwestern Polytechnic to Empower the Next Generation of Engineers

    Spartan Controls is proud to announce a 15-year partnership with Northwestern Polytechnic (NWP) as the exclusive naming sponsor for the institution’s new $16 million, full-service training and education space. The facility, set to open in summer 2025, will be named the Spartan Controls Northwestern Centre for Industrial Automation & Innovation. Read More…

  • Convergix: Tarriff Communication

    Convergix: Tarriff Communication

    Convergix Announces Tarriff Mitigation Plan. With the recent news regarding tariffs affecting trade between Mexico, Canada, China, and the U.S., and the indication of tariffs being imposed on the U.S. by Canada and Mexico, we want to take a moment to share the steps Convergix is taking to minimize any potential impact on our customers.… Read More…


Sponsored Content
The Easy Way to the Industrial IoT

The way to the Industrial IoT does not have to be complicated. Whether access to valuable data is required or new, data-driven services are to be generated, Weidmuller enables its customers to go from data to value the easy way. Weidmuller’s comprehensive and cutting-edge IIoT portfolio applies to greenfield and brownfield applications. Weidmuller offers components and solutions from data acquisition, data pre-processing, data communication and data analysis.

Visit Weidmuller’s Industrial IoT Portfolio.


ADVANCED Motion Controls Takes Servo Drives to New Heights (and Depths) with FlexPro Extended Environment Product Line

Advanced Motion Controls is proud to announce the addition of six new CANopen servo drives with Extended Environment capabilities to their FlexPro line. These new drives join AMC’s existing EtherCAT Extended Environment FlexPro drives, making the FlexPro line the go-to solution for motion control applications in harsh environments.

Many motion control applications take place in conditions that are less than ideal, such as extreme temperatures, high and low pressures, shocks and vibrations, and contamination. Electronics, including servo drives, can malfunction or sustain permanent damage in these conditions.

Read More


Service Wire Co. Announces New Titles for Key Executives

Bruce Kesler and Mark Gatewood have been given new titles and responsibilities for Service Wire Co.

Bruce Kesler has assumed the role of Senior Director – Business Development. Bruce will be responsible for Service Wire’s largest strategic accounts and our growing Strategic Accounts Team.

Mark Gatewood has been promoted to the role of Vice President – Sales & Marketing. In this role, Gatewood will lead the efforts of Service Wire Company’s entire sales and marketing organization in all market verticals.

Read More


Tri-Mach Announces the Purchase of an Additional 45,000 sq ft. Facility

Tri-Mach Elmira Facility

Recently, Tri-Mach Inc. was thrilled to announce the addition of a new 45,000 sq ft. facility. Located at 285 Union St., Elmira, ON, this facility expands Tri-Mach’s capabilities, allowing them to better serve the growing needs of their customers.

Positioning for growth, this additional facility will allow Tri-Mach to continue taking on large-scale projects, enhance product performance testing, and provide equipment storage for their customers. The building will also be the new home to their Skilled Trades Centre of Excellence.

Read More


JMP Parent Company, CONVERGIX Acquires AGR Automation, Expanding Global Reach

Convergix Automation Solutions has completed the acquisition of AGR Automation (“AGR”), a UK-based provider of custom, high-performance automation design and systems integration primarily to the life sciences industry.

Following Convergix’s acquisitions of JMP Solutions in August 2021 and Classic Design in February 2022, AGR marks the third investment in Crestview’s strategy to build Convergix into a diversified automation solutions provider targeting the global $500+ billion market, with a particular focus on the $70 billion global systems integration and connectivity segments. Financial terms of the transaction were not disclosed.

Read More


Latest Articles

  • HELUKABEL: Q & A With HELU – Cable Solutions for Glass Manufacturing

    HELUKABEL: Q & A With HELU – Cable Solutions for Glass Manufacturing

    HELUKABEL Provides Insights Regarding Cable Solutions in Glass Manufacturing. In the glass manufacturing industry, various types of cables play essential roles in powering equipment, monitoring temperatures, and ensuring safe, efficient operations. Due to the high temperatures, heavy machinery, and automation involved in glass production, specialized cables are required to withstand extreme conditions, transmit data reliably,… Read More…

  • Wieland: TÜV-Certified Training for Functional Safety February 24 – 28, 2025 in Mississauga

    Wieland: TÜV-Certified Training for Functional Safety February 24 – 28, 2025 in Mississauga

    Wieland: TÜV-Certified Training for Functional Safety February 24 – 28, 2025 in Mississauga. This intensive five-day course is designed for designers, developers, maintenance engineers, and safety officers seeking to enhance their expertise in functional safety. Participants will gain in-depth knowledge and practical skills to implement functional safety measures throughout the entire CE process in compliance… Read More…