Cyber security
IEC International Standards together with testing and certification (conformity assessment) are important tools for a successful cyber security strategy. They need to be incorporated into an overarching strategy that includes people, processes and technology.
Horizontal Standards
The ISO/IEC Joint Technical Committee (JTC1 ) develops the ISO/IEC 27000 family of Standards for information technology (IT) systems. IEC Technical Committee 65 (TC 65) has created IEC 62443 for operational technology found in industrial and critical infrastructure, including but not restricted to power utilities, water management systems, healthcare and transport systems. These are horizontal standards, which are technology independent and can be applied across many technical areas.
Vertical Standards
Vertical Standards are designed to meet specific technical needs, for example in the energy sector, manufacturing, healthcare or shipping, among others. Several technical committees (TCs) and subcommittees (SCs) prepare International Standards that protect specific domains and keep industry and critical infrastructure assets safe. Here is a short selection:
protection of microprocessor-based information and control systems in nuclear power plants |
Nuclear power plants (NPPs) |
||
framework for managing the interactions between safety and cyber security. |
|||
series of publications for communication networks and systems for power utility automation |
Electric power utilities |
||
series for telecontrol equipment and systems |
|||
series on power systems management and associated information exchange |
|||
ISO/IEC 80001 |
risk management for IT-networks incorporating medical devices |
Healthcare |
|
series of publications that specify security requirements for industrial automation and control systems (IACS) |
Industry |
||
series for maritime navigation and radiocommunication equipment and systems |
Shipping |
Related publications and brochures
Conformity Assessment
IECEE has created global certification services based on the IEC 62443 series.
Standards provide written instructions. Testing and certification (conformity assessment) verifies that these instructions are properly applied in real-world technical systems.
The IEC runs four conformity assessment systems with up to 54 member countries. In the area of cyber security, IECEE currently plays the lead role in providing services based on the IEC 62443 series of Standards. IECEE Industrial Cyber Security Programme was created to test and certify cyber security in the industrial automation sector.
The IECEE “operational document” OD-2061 describes how conformity assessment can be applied to the IEC 62443 series.
Related e-tech articles
