Overview
IEC TR 62351-10:2012 - "Power systems management and associated information exchange - Data and communications security - Part 10: Security architecture guidelines" - is a Technical Report from IEC TC 57 that provides hands-on security architecture guidelines for power systems. It focuses on essential security controls (components, functions and interactions) and maps those controls to the general TC 57 power system architecture to help system integrators securely deploy generation, transmission and distribution systems. Edition: 1.0 (2012-10).
Key Topics
- Security architecture for power systems: practical guidance on how to structure security across system layers rather than pure theory.
- Security domains and domain mapping: defining security domains relevant to power systems and mapping them to power-system-specific domains.
- Security controls: identification and categorization of essential security controls (including network-based controls) and guidance for determining required controls per use case.
- Mapping to TC 57 reference architecture: aligning security controls with IEC TC 57 components and interfaces to support interoperability.
- Interface categories & protocol mapping: correlating NIST-style interface categories with TC 57 interfaces and mapping IEC 62351 protocol-related parts to the IEC 61850 stack and other TC 57 standards.
- Deployment scenarios & examples: practical examples including substation automation, control center - substation communication, and advanced metering infrastructure (AMI).
- Secure lifecycle considerations: guidance on secure design, development and operation processes and a system security assessment approach.
- Gaps and further material: identified gaps in existing standards and pointers to related standards and regulatory frameworks.
Practical Applications
- Secure design and integration of SCADA and substation automation systems.
- Applying security controls when deploying IEC 61850, IEC 60870-5 and other TC 57 protocols.
- Guiding utility security architects and system integrators in mapping cybersecurity requirements to the power system architecture.
- Informing risk assessments, procurement specs and secure configuration for AMI, control centers and field devices.
- Supporting compliance and alignment with regulatory frameworks (e.g., NERC CIP) by translating security controls into architecture-level guidance.
Who Should Use This Standard
- Power system engineers and system integrators
- Utility security architects and operations teams
- OT/SCADA cybersecurity engineers
- OEMs of protection, automation and control equipment
- Compliance and risk management professionals in the energy sector
Related Standards
- IEC 62351 series (data & communications security)
- IEC 61850 (substation automation)
- IEC 60870-5 (telecontrol)
- NERC CIP and NIST guidance (interface/security categories)
IEC TR 62351-10 is an informative, implementation-focused resource to bridge protocol-level security controls with system architecture for secure Smart Grid and power system deployments.