IEC TR 62443-2-3:2015
Security for industrial automation and control systems - Part 2-3: Patch management in the IACS environment
Security for industrial automation and control systems - Part 2-3: Patch management in the IACS environment
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 61
- Дата публикации:
- 30 июня 2015 г.
- Издание:
- IEC TR 62443 edition 1 version 1
- ICS:
- 25.040.40
IEC TR 62443-2-3:2015(E) describes requirements for asset owners and industrial automation and control system (IACS) product suppliers that have established and are now maintaining an IACS patch management program. This Technical Report recommends a defined format for the distribution of information about security patches from asset owners to IACS product suppliers, a definition of some of the activities associated with the development of the patch information by IACS product suppliers and deployment and installation of the patches by asset owners. The exchange format and activities are defined for use in security related patches; however, it may also be applicable for non-security related patches or updates.
Abstract
Overview
IEC TR 62443-2-3:2015 is a technical report developed by the International Electrotechnical Commission (IEC) focusing on security for industrial automation and control systems (IACS), with a particular emphasis on patch management within the IACS environment. It addresses the specific requirements, responsibilities, and recommended processes for both asset owners and product suppliers who have established and are actively maintaining an IACS patch management program.
This guidance is crucial for industries relying on automation and control systems, as effective patch management is a cornerstone of cyber security, system reliability, and operational safety. The document encourages a standardized exchange format for security patch information and sets out best practices for both the development and deployment of patches, specifically for IACS environments.
Key Topics
IEC TR 62443-2-3:2015 covers the following essential aspects:
- Patch Management Program Requirements: Outlines what is expected from asset owners and product suppliers in organizing, maintaining, and improving their patch management processes.
- Patch Information Exchange Format: Recommends standardized methods for exchanging security patch information to ensure compatibility and efficient deployment.
- Patch Lifecycle: Defines the various lifecycle stages of patches, from identification and testing through authorization and final installation.
- Challenges in IACS Patching: Recognizes the unique obstacles in patching industrial systems, such as ensuring system safety, minimizing downtime, and maintaining operational reliability.
- Roles and Responsibilities: Clarifies the obligations of both asset owners and IACS product suppliers throughout the patch management lifecycle.
- Testing and Validation: Highlights the need for thorough testing of patches to prevent system incompatibilities or operational issues.
- Mitigation for Obsolete Systems: Suggests risk mitigation practices for IACS assets that are no longer supported by suppliers but still operate in critical environments.
Applications
Implementing the recommendations of IEC TR 62443-2-3:2015 brings practical benefits to organizations operating industrial automation and control systems:
- Enhanced Cyber Security: Prompt and structured application of security patches helps reduce vulnerabilities and prevent cyber incidents in industrial environments.
- Reduced Operational Risks: Systematic patch management mitigates the risk of disruptions, safety hazards, and quality issues associated with unpatched systems.
- Regulatory Compliance: Following this standard helps organizations meet or exceed industry regulations and auditing requirements targeting industrial cyber security and system reliability.
- Improved Collaboration: Clear definitions for information exchange promote better communication between asset owners and suppliers, leading to faster resolution of vulnerabilities.
- Sustained System Integrity: Ongoing patch management supports long-term reliability and efficiency of industrial assets, even when dealing with legacy or unsupported equipment.
Industries benefiting from this standard include oil and gas, manufacturing, pharmaceuticals, energy, water treatment, and any sector that relies on automated control systems for mission-critical operations.
Related Standards
To ensure a comprehensive approach to industrial cyber security and patch management, reference can also be made to the following related standards:
- IEC TS 62443-1-1: Provides terminology, concepts, and models for IACS security.
- IEC 62443-2-1: Specifies requirements for establishing an IACS security management system.
- ISO/IEC 27001 & ISO/IEC 27002: Establish information security management systems guidelines, supporting broader organizational information security framework.
- Other IEC 62443 Series Standards: Several documents in this series further detail technical, process, and organizational aspects of IACS security.
By aligning with IEC TR 62443-2-3:2015, organizations can improve their patch management process, enhance resilience against threats, and ensure the safe, reliable operation of their industrial automation and control systems.
Технические детали
- Технический комитет
- TC 65 - Industrial-process measurement, control and automation
- SKU
- IEC TR 62443-2-3:2015
Похожие стандарты
Стандарты, упомянутые в описании
IEC 62443-2-1:2010
ДействующийIndustrial communication networks - Network and system security - Part 2-1: Establishing an industrial automa…
Overview IEC 62443-2-1:2010 specifies the elements required to establish a Cyber Security Management System (CSMS) for Industrial Automation and Control Systems (IACS). Part of the IEC 62443 series o…
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…
IEC 62443-3-3:2013
ДействующийIndustrial communication networks - Network and system security - Part 3-3: System security requirements and…
Overview IEC 62443-3-3:2013 - Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels - defines detailed technical requirements fo…