Overview
IEC 62859:2016 is an international standard developed by the International Electrotechnical Commission (IEC) that addresses the critical coordination between safety and cybersecurity in nuclear power plant (NPP) instrumentation and control (I&C) systems. Given the evolution from traditional non-digital systems to interconnected programmable digital systems within NPPs, this standard provides a structured framework to effectively manage the interactions and potential conflicts that arise between safety measures and cybersecurity controls.
Specifically tailored for nuclear I&C programmable digital systems, IEC 62859 establishes requirements and guidance for integrating cybersecurity provisions into safety-critical architectures, ensuring that these provisions complement rather than conflict with safety objectives. The standard is essential for NPP designers, operators, vendors, evaluators, and licensors to manage risks while maintaining both operational safety and system security.
Key Topics
-
Safety and Cybersecurity Coordination
IEC 62859 highlights the importance of integrating cybersecurity controls within safety-oriented I&C architectures without compromising safety functions. It includes methods to identify potential conflicts and leverage synergies between these domains.
-
Architecture-Level Requirements
The standard addresses security zoning, separation provisions, and methods for handling common cause failures, particularly those that could affect both safety and cybersecurity simultaneously.
-
System-Level Lifecycle Activities
It covers coordination throughout the I&C system lifecycle, including design, implementation, verification, validation, operation, maintenance, change management, and decommissioning to ensure ongoing safety and security compliance.
-
Technical Controls in I&C Systems
Important aspects covered include logical access control for human-machine interfaces (HMI), software modification safeguards, logging and audit capabilities, use of cryptographic techniques, and ensuring system availability and functional continuity.
-
Organizational and Operational Governance
IEC 62859 emphasizes governance structures that define clear responsibilities for safety and cybersecurity teams, encourages a robust safety and cybersecurity culture, and outlines emergency response management for incident preparedness.
Applications
-
Nuclear Power Plant Design and Operations
Ensuring that digital I&C systems meet both safety and cybersecurity requirements by following IEC 62859 can significantly reduce operational risks from cyber threats while maintaining essential safety standards.
-
System Evaluations and Licensing
Vendors, evaluators, and licensing authorities rely on this standard as part of their compliance strategies to verify that safety and cybersecurity provisions are harmonized in digital control systems.
-
Risk Management in Nuclear Facilities
The standard provides a framework to identify and mitigate risks stemming from interactions between safety and cybersecurity systems, improving overall resilience of nuclear power plant operations.
-
Integration into Safety and Security Policies
Utilities and operating organizations can incorporate IEC 62859 requirements into their internal policies and procedures to foster coordinated governance and operational practices.
Related Standards
-
IEC 61513 – Focuses on general requirements for instrumentation and control systems important to safety in nuclear power plants and serves as a top-level document within IEC Subcommittee 45A (SC 45A).
-
IEC 62645 – Addresses cybersecurity specifically for nuclear I&C systems and is considered complementary to IEC 62859, with both standards forming the second tier of SC 45A’s documentation hierarchy.
-
Other SC 45A Standards – IEC 62859 is part of the comprehensive series developed by IEC SC 45A concerning nuclear instrumentation and control, integrating seamlessly with broader nuclear safety and cybersecurity frameworks.
Keywords: IEC 62859, nuclear power plants, instrumentation and control, I&C systems, cybersecurity, safety coordination, programmable digital systems, nuclear safety, cyber threats, safety and cybersecurity integration, nuclear I&C architecture, IEC standards, risk management, digital control systems, nuclear facility security.