DCS; Industrial control system
NameDescriptionContent
NEW CENTER
Current Location:

Understanding the ISA/IEC 62443 Series of Standards

来源:automation | 作者:H | 发布时间 :154 days ago | 16 次浏览: | Share:
Understanding the ISA/IEC 62443 Series of Standards
Understanding the ISA/IEC 62443 Series of Standards

Digital transformation paves the way for businesses to improve efficiency, reduce errors, improve overall equipment effectiveness (OEE) and reduce costs. With the promise of operational technology (OT) advances, comes the need for protecting assets through painstakingly applying cybersecurity principles.

To ensure that businesses are on the same cybersecurity page, a best practice is to adopt and follow established criteria such as the ISA/IEC 62443 series of standards.

The International Society of Automation (ISA) established the ISA99 standards committee in 2002, recognizing the need to secure equipment and operations that comprise U.S. critical infrastructure against cyberattacks. Since then, ISA99 has published a comprehensive family of standards and technical reports purpose-built to address securing automation and control systems.

The ISA/IEC 62443 standards are submitted to the International Electrotechnical Commission (IEC) for global adoption as international standards ISA/IEC 62443. The ISA/IEC 62443 series of standards are endorsed by the United Nations. With use cases from more than 20 different industries, the ISA/IEC 62443 series of standards has demonstrated its utility in all industry verticals that use operational technology systems. In 2021, IEC recognized the series as a horizontal standard, meaning that they have been proven to apply to a broad range of different industries.

The IEC 62443 series of standards addresses cybersecurity for OT in automation and control systems. The series is divided into different sections and describes both technical- and process-related aspects of automation and control system cybersecurity. The series is also known as ISA/IEC 62443 in recognition of the fact that much of the initial development was done by the ISA99 committee of ISA.

Cybersecurity topics are divided by stakeholder category/roles including:

  • the operator

  • the service providers (system integration and maintenance)

  • the component/system manufacturers.

The different roles follow a risk-based approach to prevent and manage security risks in their activities. The ISA/IEC 62443 series of standards defines requirements and processes for implementing and maintaining electronically secure industrial automation and control systems (IACS). These standards set best practices for security and provide a way to assess the level of security performance. Their approach to the cybersecurity challenge is holistic, bridging the gap between OT and information technology (IT) as well as between process safety and cybersecurity.
 

900 volunteers contribute

Steve Mustard, president of National Automation Inc. and former ISA president (2021) explained the work that goes into creating and maintaining the standards. “It’s not just a standard, it’s a multiple set of documents,” he said. “The first versions were in 2005, ‘06, ‘07 and ‘08, and they’re being updated now because they get updated every five years. It became an IEC standard and incorporated Part 2-4 from IEC into that set.”

Mustard said there are around 900 volunteers from all over the world on the ISA99 committee. “Some write content, some review content and some vote on content. They’re in different companies. They’re asset owners, vendors, consultants and educators. They all contribute their time freely. Not all of them are members of ISA, but we’d like them to be,” he added.

“We also have a lot of experts from government organizations and non-government organizations,” continued Mustard. “They put a lot of time in, continuously developing different parts of the standard and technical reports, which are documents that help explain some of the detail in the normative versions of the standards and how you execute that. It’s a lot of work.”

Currently, there is certification for products and systems, and then the development lifecycle for vendors. These standards set cybersecurity benchmarks in all industry sectors that use IACS, including building automation, electric power generation and distribution, medical devices, transportation and process industries such as oil and gas and chemicals.

“Very soon, there will be a site-level assurance program,” explained Mustard. “Parts 2-1 and 3-3 [of ISA/IEC 62443] and many of the other parts of the standard are covering all the requirements in there, much like ISO27001. All the vendors who come along are providing their pieces, but someone has to put them together. The individual projects are great, but it’s the whole ecosystem that you have to certify or validate that the risk is being managed.”
 

Communicating with others

Chris McLaughlin, chief information security officer (CISO) at Johns Manville and one of the many ISA volunteers who are developing the standard, said, “I’d love for there to be an ISO certification at some point. What’s important to us is to be able to demonstrate to physical insurance providers that we have a program that’s working. But at the first stages, you’re just focused on getting all the pieces.”

McLaughlin said insurance companies are asking about cybersecurity. At Johns Manville, he said, “Our physical insurance companies have been doing cyber assessments at each one of our plant locations. Those are our big assets. It would be a big loss if you lost a whole production facility; that’s a significant impact, not just a short-term impact. The insurance companies are asking a lot more cyber questions; they’re asking for network maps. I don’t want to give my insurance provider all those details, so we say: ‘We follow these controls. This is how we generally do it, and we have a third party that has audited it.’”

Anna Burrell, an OT cybersecurity consultant with Deloitte, said, “You have to make sure you’re [implementing ISA/IEC 62443] across all of your estate. These cyber incidents don’t care if it’s on a site. It’s going to hit a business and it’s going to either come into your sites and your OT networks and move up, or it’s going to come in the top and move down. So how do you holistically manage all of that risk end to end?”

“ISA/IEC 62443 is a toolset,” explained Burrell. “It’s a standard to give structure and organization in a way that engineers understand. The way you choose to implement those controls works with other policies and standards. It references that it has to work in conjunction with organizational policies and it gives a structure and a common language. It helps people work together to say, ‘How are we going to do this?’”

Burrell said, “You can assure against [62443] because you can check things, but it’s not enforcing how you do things. I think that’s how it’s different and why it applies across industries and sites, projects and organizations. It’s much wider than necessarily some of the more specific [standards].”
 

The owner/system integrator relationship

Businesses that own automation assets must ensure system integrators are delivering systems that meet specified requirements. System integrators must be involved in the process. Part 2-4 of the standard helps integrators understand the asset owners’ needs so they can convey the essence of those needs to asset owners, which benefits the owner/integrator relationship.

Mustard expressed that Part 2-4 is very much about requirements for system integrators and maintenance providers. “It provides a comprehensive list of requirements that an asset owner would want from a vendor, system integrator or maintenance provider. They’re dealing with multiple organizations, which, without the standard, have their own set of requirements that are similar but not identical. If they all use the same standard, it makes their life a lot easier in terms of responding to the requirements,” he said.

Consider BP, for example, Mustard continued. When they have contracts for work in system integration or maintenance, they develop their own set of requirements that are BP-specific. If you go to Shell, they have their own. They build requirements based on what they have done in the past. They may not necessarily incorporate all the requirements that ISA/IEC 62443 has. “When you have a project, there’s a lot of requirements about basic cyber hygiene you need to do, and those get overlooked sometimes in contracts,” he said.

“If you use ISA/IEC 62443-2-4 as the basis, you have everything covered so you’re not going to forget anything. My recommendation is for asset owners to adopt Part 2-4, and also for the system integrators and maintenance providers to read and understand it and be prepared to respond when asset owners put out a request for services in line with that standard,” Mustard explained.

“The integrator delivers solutions that are meeting those requirements,” explained Burrell. “But ultimately, it’s up to the business who owns these systems to make sure the integrators are delivering systems that meet the requirements to the specified level while testing and validating that the services and the maintenance contracts have been done to meet the requirements and manage that risk across the business.”

“The integrators must deliver solutions to meet the requirements, to make sure that the technology can be implemented securely, or the components are certified and meeting those objectives,” Burrell continued. “But as an asset owner, you have to put that technology into your organization in the right way, make sure it’s meeting your need, and ensure the risk is being managed so that these systems are operating correctly while keeping yourselves safe and production working.”
 

Final thoughts

Training people on ISA/IEC 62443 is an ongoing task. “We find that there’s a shortage of talented people in this space,” said Andre Ristaino, managing director at ISA. “We’ve been funding the development of training classes. For product suppliers, there’s a class called ‘IC47.’ It covers the standards associated with product development. It’s a three- or four-day class, and it also has modules that address requirements for product assessors. We saw that there was a gap with the product assessors at our certification bodies. We’re trying to fill that void as well, and we expect to do additional training in the future.”

“The ISA/IEC 62443 series of standards is out there and information about what needs to be done by asset owners, system integrators and product suppliers is all in there,” said Mustard. “I think people need to follow it. I think product suppliers and system integrators need to do it regardless of whether asset owners ask them to do it because it’s the right thing to do. I think asset owners need to understand the totality of what they need to do, and it’s in there. Certification programs will help provide the verification that it’s being done.”

“Things have improved a lot,” continued Mustard. “A few years ago, we would be talking about 62443 and half the audience wouldn’t have known what it was. It’s encouraging to see so many people who already understand it, and where people are actually applying it and doing real practical things with it. I’m encouraged by that, but we still have a long way to go.”


Additional Resources on ISA/IEB 62443

More information on the ISA/IEC 62443 series of standards can be found on the ISA website. There you will find links to the following resources.

  • Published Standards and Technical Reports

  • ISA Cybersecurity Certificate Training Program

  • ISA Global Cybersecurity Alliance (ISAGCA) website

  • Quick Start Guide to ISA/IEC 62443

  • Guide to Security Lifecycles in ISA/IEC 62443

  • IACS Taxonomy Glossary

  • IACS Principal Roles and Responsibilities

  • Overview of ISASecure Certification for ISA/IEC 62443

  • IoT Security Maturity Model: 62443 Mappings for Asset Owners and Product Suppliers

  • ISASecure website for Supplier and Product Certification

This feature originally appeared in AUTOMATION 2024: 1st Annual OT Cybersecurity Trends Report.


  • GE Fanuc - IS200EXHSG3A High-Speed Relay Driver Terminal Board for Exciters
  • GE IS200TRLYH1BGF - Advanced Relay Termination Circuit Board for Industrial Control
  • GE A06B-6151-H075 - Spindle Amplifier Module High Precision Control for Industrial Applications
  • GE DS200TBQDG1A - Advanced Extension Analog Termination Board for Industrial Control Systems
  • GE IC697CMM742-HK - Advanced Ethernet Module for Industrial Automation
  • GE IC200CHS002 - Box-Style Input/Output Carrier
  • GE VME-MB-Z004 - MODULE Advanced Industrial Control Solutions
  • GE IS200ERDDH1ABB - High-Performance Circuit Board for Speedtronic System
  • GE IS210AEBIH3BE - Printed Circuit Board
  • GE MIWII - 1000E00HI00 High Precision Counter Module
  • GE Electric - IC693MDL931 Isolated Relay Output Module
  • GE Fanuc - IS215UCVEH2AE Advanced Gas Turbine Control System
  • GE 531X111PSHARG3 - Industrial Power Supply Card
  • GE DS200TCQCG1RJD - Power Supply Board for Industrial Control Systems
  • GE IC693PRG300 - G300 Hand-Held Programmer
  • GE FANUC - 78004654B High Performance Industrial PLC Module
  • GE A06B-6093-H101 - Servo Amplifier Unit Precision Control for Advanced Applications
  • GE DS200TCPDG2BEC - A Comprehensive Power Distribution Board for Industrial Control Systems
  • GE DS3800NPSJ1B1B - High-Performance Power Supply Board for Industrial Control Systems
  • GE GE - IS200GFOIH1A High-Performance Control Module for Industrial Automation
  • GE IS215ACLEH1AB - Original Equipment Manufacturer Control Module
  • GE Fanuc - F650BABF2G0IHI PLC Module High-Performance Control Core
  • GE DS200ADPBG1ABB - Precision Engineered Genius Adapter Module for Advanced Control Solutions
  • GE IS210HSLAH1ADE - High-Speed Serial Link Interface Circuit Board
  • GE IS215GFOIH1A/IS215GFOIH1AB/IS200GFOIH1A - Industrial Control Systems for Enhanced Performance & Reliability
  • GE CM415REBKH1B - Tuning Fork Crystal Unit for Industrial Control Systems
  • GE Fanuc - IC694MDL916 Advanced Programmable Automation Controller
  • GE Fanuc - SR469-P5-HI-A20 Motor Protection System Comprehensive Control for Large Motors
  • GE Electric - IC693ALG221 Affordable Industrial Control Module
  • GE Electric - DS200TCQRG1RFC Circuit Board Advanced IO Expansion Module
  • GE FANUC - IC694MDL740 Modular Control System Module
  • GE IC697MDL753 - Industrial Output Module Precision Control for Your Operation
  • GE DS3800HAFA1D - Industrial Control Module for Power Generation
  • GE DS200TCDAG1A - Advanced Digital I/O Board for Industrial Control
  • GE UR6TH - Module Digital Input/Output
  • GE FANUC - DS200SNPAH1ABB Advanced Gas Turbine Control Module
  • GE IS220PSCAH1A - IO Pack for Serial Communications
  • GE Fanuc - IC698PSA100E Durable Industrial Power Supply Module
  • GE IC693PWR322 - High-Performance Power Supply for Industrial Control Systems
  • GE FANUC - IC697CPM925 CPU MODULE Industrial Control Solution
  • GE IC3600SSLB1H1B - Gas Turbine Control Module
  • GE DS3800HPRB1A1A - Precision Pulse Rate Card for Industrial Control Systems
  • GE DS4820R20 - Relay Module (194B5704G1) Reliable Industrial Control Solution
  • GE IC698CHS009 - Rear Mounted Rack Industrial Control Module
  • GE IC694ALG392 - Analog Output Module for Industrial Control Systems
  • GE DS200TCDAH1BGD - Advanced I/O PC Board for Industrial Automation
  • GE Electric - DS200TCEAG1BTF Emergency Overspeed Board
  • GE IS420YAICS1B - Analog I/O Module for Industrial Control Applications
  • GE Fanuc - IC693PWR331CA High-Efficiency Power Supply for Industrial Control Systems
  • GE UR9NH - CPUUR PLC CPU Module
  • GE SR735-5-5-HI-485 - Relay
  • GE Fanuc - 0285A7595 MGM115 Programmable Logic Controller Module
  • GE Fanuc - IC200MDL102 Input Modules Advanced Control Solutions
  • GE M60K03HKHF8LH4CM8NP6EUXXW5C - Industrial Control Module
  • GE Industrial - Systems IS200BICIH1ADC PCB Board
  • GE IC200CPU001 - Advanced Microcontroller Module
  • GE DS200TCQCG1BJF - PLC Overflow Board
  • GE Fanuc - IS200TRPGH1B Terminal Board Advanced Control Solution for Industrial Automation
  • GE IC693CPU313LT - Advanced Series 90-30 PLC Controllers
  • GE Industrial - Controls 8601-FT-NI Field Terminal Module
  • GE IC200CHS001 - Industrial Control System I/O Carrier
  • GE IC693CHS397M - High-Performance Programmable Logic Controller Module
  • GE 0552N1QLG132A-01 - Control Module Advanced Industrial Automation Solution
  • GE A20B-1006-0270 - Keyboard Panel High-Performance Control Module
  • GE IS210AEAAH1BKE - Industrial Strength Mark VI PCB for Enhanced Turbine & Excitation Control Systems
  • GE Fanuc IC200UAL005 Versamax PLC - Industry-Leading Control Solution
  • GE IC693PWR330 - Industrial Power Supply
  • GE IC200ALG620 - Industrial Input Module
  • GE DS200SLCCG3ACC - & DS215DENCG3AZZ01A | Industrial Communication Board
  • GE DS3800HPIB - Industrial Grade Panel Interface Board for Turbine Control
  • GE DS200SDCIG2AFB - High-Performance SDCI Board for Industrial Automation
  • GE IS200MVREH1AAB - Advanced Control Board for Industrial Automation
  • GE DS3820RDMB - Control Card Precision in Automation
  • GE FANUC - VMIVME-7671-421000
  • GE DS200SLCCG3AGH - Advanced Industrial Control System
  • GE IC695CPE330 - Dual-Core Microprocessor Industrial Control Module
  • GE Fanuc - DS200LDCCH1A Advanced Mark V PLC for Industrial Control
  • GE IS200XDIAG1A-DD - Advanced Circuit Board PLC for Industrial Automation
  • GE IS200ACLAH1A - Advanced Control Assembly
  • GE Fanuc - IC697CPM790 PLC Control Module
  • GE UR6EH - I/O Module for Advanced Industrial Automation
  • GE Fanuc - IC693CPU374HW PAC Systems RX3i
  • GE Electric - IS220YDOAS1AK Analog I/O Pack Industrial Automation Solutions
  • GE FANUC - VMIPCI-5565-110000 Advanced Reflective Memory Node Card for Industrial Automation
  • GE Fanuc - HE693STP311 Indexer Stepper Motor High Performance for Industrial Control Systems
  • GE Fanuc - IS230SNAIH4A/IS200STAIH2ACB Precision Control for Industrial Automation
  • GE IC200MDL740J - Output Module Advanced Control Solutions for Industrial Automation
  • GE FANUC - 745-W2-P5-G5-HI-A-L | Advanced Transformer Protection System
  • GE Electric - DS200TCDAH1 Digital I/O Board Control Systems
  • GE FANUC - IC660BBR101 Relay Block High Performance Modular PLC Component
  • GE FANUC - DS200ADMAH1AAC Precision Digital-Analog Module for Industrial Control Systems
  • GE Fanuc - IC697VAL314 Programmable Automation Controller
  • GE HE693RTM705C - RTU Master Module
  • GE DS200FCSAG2ACB - Advanced Control System Module for Industrial Automation
  • GE Fanuc - IC200TBM002 | Versamax PLC Modular Control Heart
  • GE VMIPMC-5565 - Memory PMC Modules
  • GE IC687BEM744 - High-Performance Bus Controller
  • GE Electric - IS215ACLEH1AB
  • GE HE700GEN100 - Advanced VME Interface Module for Industrial Control Systems
  • GE IS200HFPAG2ADC - Precision Circuit Board for Industrial Control Systems
  • GE Electric - 0621L0431-G001 Armature Interface Card
  • GE FANUC - DS303A6A01KXA003XT Advanced Direct Current Contactor
  • GE Electric - IC641HBR302 Programmable Logic Controller Module
  • GE UR9WH - Multilin Ur Relay Module Advanced Control
  • GE IC200MDL240 - AC Input Module
  • GE Electric - IS420UCSCH2A-C-V0.1-A Unique Turbine Control System Module
  • GE IS200EXHSG3AEC - High-Speed Relay Driver for Turbine Control Systems
  • GE IC697ALG320 - Analog Output Module for Industrial Control Systems
  • GE IC200CHS002M - Industrial Control Module by GE-FANUC
  • GE IS200AEPCH1BAA - High-Performance Printed Circuit Board Module for Industrial Automation
  • GE IC693DSM302-RE - Digital Signal Processor Module
  • GE DS200SIOBH1ABA - High Performance Signal Input Module for Industrial Automation
  • GE Electric - IC660BBA026 Analog Input Module
  • GE Electric - DS200FCGDH1B DSP Drive Control Module
  • GE DS200TCEAG1BTF - Advanced Processor Card for Industrial Control Systems
  • GE FANUC - IC698CPE020-JU CPU MODULE Advanced Control
  • GE IC694MDL931 - RX3i AC/DC Voltage Output Module
  • GE IS420UCECH1B - Industrial Control System for Precision Applications
  • GE IC200ALG240 - Industrial Control Module
  • GE 8103AI-TX - Analog Input Module
  • GE FANUC - IC695PSD140 Power Supplies Industrial Control Solutions
  • GE DS200TCQCG1AFC - Relay Board for Industrial Control Systems
  • GE IS230SNAIH4A - & IS200STAIH2ACB Industrial PLC Circuit Board
  • GE FANUC - IC697VAL348 Digital to Analog Converter Board for Industrial Control
  • GE IS200WETCH1AAA - Precision Converter Power Module for Industrial Control Systems
  • GE IC695CPU320 - CF High Performance Modular Control CPU
  • GE FANUC - IC697MDL671 Interrupting Module Advanced Control
  • GE DS3800HSAA1T1M - Servo Amp