IEC 62645:2019
Nuclear power plants - Instrumentation, control and electrical power systems - Cybersecurity requirements
Nuclear power plants - Instrumentation, control and electrical power systems - Cybersecurity requirements
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 112
- Дата публикации:
- 13 ноября 2019 г.
- Издание:
- IEC IS 62645 edition 2 version 1
- ICS:
- 27.120.20
IEC 62645:2019 establishes requirements and provides guidance for the development and management of effective computer security programmes for I&C programmable digital systems. Inherent to these requirements and guidance is the criterion that the power plant I&C programmable digital system security programme complies with the applicable country’s requirements. This document defines adequate measures for the prevention of, detection of and reaction to malicious acts by digital means (cyberattacks) on I&C programmable digital systems. This includes any unsafe situation, equipment damage or plant performance degradation. This second edition cancels and replaces the first edition published in 2014. This edition includes the following significant technical changes with respect to the previous edition: a) to align the standard with the new revisions of ISO/IEC 27001; b) to review the existing requirements and to update the terminology and definitions; c) to take account of, as far as possible, requirements associated with standards published since the first edition; d) to take into account the fact that cybersecurity techniques, but also national practices evolve.
Abstract
Overview
IEC 62645:2019 is an international standard developed by the International Electrotechnical Commission (IEC) that sets forth cybersecurity requirements for nuclear power plants, specifically focusing on Instrumentation, Control, and electrical power systems. This standard addresses the development and management of comprehensive computer security programs aimed at protecting I&C (Instrumentation & Control) programmable digital systems from cyber threats. It emphasizes compliance with country-specific regulations and guides organizations on effective prevention, detection, and response to cyberattacks that could cause unsafe conditions, equipment damage, or operational degradation. The 2019 edition updates the 2014 version by aligning with ISO/IEC 27001, refining terminology, and integrating recent cybersecurity and national practice developments.
Key Topics
-
Cybersecurity Program Management:
IEC 62645 outlines the framework for establishing, managing, and continuously improving computer security programs covering all phases-from development and implementation to operation and retirement of I&C systems. It stresses leadership commitment, clear roles, and documented policies to ensure robust cybersecurity governance. -
Risk Assessment and Graded Approach:
The standard advocates a risk-based, graded approach to cybersecurity tailored to the significance of specific I&C systems. It provides methods for identifying security degrees based on safety categories, operational impact, and performance degradation risks. -
Lifecycle Security Implementation:
Comprehensive lifecycle guidance covers system specification, detailed design, integration, validation, installation, operation, maintenance, and retirement phases. This ensures security considerations are embedded throughout the system’s evolution. -
Security Controls and Defense-in-Depth:
IEC 62645 promotes defense-in-depth strategies, recommending layered security controls to mitigate vulnerabilities. This includes secure architecture, communication pathways protection, security zones definition, and continuous reassessment of controls. -
Alignment with International Standards:
The 2019 edition harmonizes with ISO/IEC 27001:2013 requirements, supporting integration into existing cybersecurity management systems. It also correlates with other IEC SC 45A standards and the IEC 62443 series, enhancing consistency in the nuclear cybersecurity domain.
Applications
IEC 62645:2019 is primarily designed for nuclear power plants but offers valuable guidance for cybersecurity in I&C programmable digital systems across various nuclear-related facilities, such as research reactors, fuel cycle plants, and small modular reactors (SMRs). The standard helps organizations:
- Develop and maintain effective cybersecurity programs to protect critical operational systems from cyber threats.
- Assess and mitigate cybersecurity risks based on system safety impact and plant availability considerations.
- Implement lifecycle security measures that reduce vulnerabilities during design, operation, and maintenance phases.
- Comply with national and international regulations for nuclear facility cybersecurity.
- Enhance resilience against cyberattacks that can cause safety hazards, equipment failure, or productivity losses.
By adhering to IEC 62645, nuclear operators improve the reliability and safety of their I&C systems, safeguarding critical infrastructure from emerging cyber risks.
Related Standards
-
ISO/IEC 27001:2013 – Information Security Management Systems (ISMS)
IEC 62645 aligns its cybersecurity program requirements with ISO/IEC 27001, facilitating integration with broader organizational ISMS frameworks. -
IEC 62443 Series – Industrial Automation and Control Systems Security
There is a high-level correspondence between IEC 62645 and the IEC 62443 standard series, which focuses on cybersecurity for automation and control systems in industrial environments. -
IEC 61513 – Nuclear Power Plant Instrumentation and Control Systems – General Requirements for Systems Important to Safety
Safety categorization processes in IEC 62645 reference criteria established in IEC 61513 to determine security degree assignments. -
Other IEC SC 45A Standards
These standards cover various aspects of instrumentation, control, and electrical power systems, complementing IEC 62645 by providing additional guidance for cybersecurity in nuclear environments.
Adopting IEC 62645:2019 assists nuclear power plants and associated facilities in establishing rigorous cybersecurity practices for their critical I&C programmable digital systems, balancing safety, reliability, and regulatory compliance effectively.
Технические детали
- Технический комитет
- SC 45A - Instrumentation, control and electrical power systems of nuclear facilities
- SKU
- IEC 62645:2019
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
IEC 62645:2014
ДействующийNuclear power plants - Instrumentation and control systems - Requirements for security programmes for compute…
Overview IEC 62645:2014 is an international standard published by the International Electrotechnical Commission (IEC) focusing on security programmes for computer-based instrumentation and control (I…
IEC 62443-3-3:2013
ДействующийIndustrial communication networks - Network and system security - Part 3-3: System security requirements and…
Overview IEC 62443-3-3:2013 - Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels - defines detailed technical requirements fo…
IEC 61513:2026
ДействующийNuclear power plants - Instrumentation and control important to safety - General requirements for systems
Overview IEC 61513:2026 “Nuclear power plants - Instrumentation and control important to safety - General requirements for systems,” published by the International Electrotechnical Commission (IEC),…