IEC TR 63415:2023 PDF
Nuclear Power plants - Instrumentation and control systems - Use of formal security models for I&C security architecture design and assessment
Nuclear Power plants - Instrumentation and control systems - Use of formal security models for I&C security architecture design and assessment
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 56
- Дата публикации:
- 30 августа 2023 г.
- Издание:
- IEC TR 63415 edition 1 version 1
- ICS:
- 27.120.20
IEC TR 63415:2023 provides an overview over the formalized modelling and designing of cybersecure architectures to apply for I&C system cybersecurity enforcement at NPPs. The plant-specific risk assessment can use the techniques covered by this TR. This document considers the complex problem of NPP I&C architecture synthesis to address particular issues: - asset classification, - barrier measures assignment, - the information transfer and links conformity with security requirements. This document provides guidance on creating a comprehensive security model applicable to NPP I&C systems that describes NPP I&C cybersecurity architecture and aids in accomplishing the main tasks of I&C system secure design, which are: - specification of system designs with increased determinism that enhance security, - mapping of the security requirements into the security architecture of the I&C system, - definition of the security requirements for information exchange between components within the I&C system, operators and other systems, - assistance in the determination of the security degree assignment with a model-based technique considering asset properties and formal grouping of the assets, design and establishment of security zones boundaries.
Abstract
Overview
IEC TR 63415:2023 - "Nuclear power plants - Instrumentation and control systems - Use of formal security models for I&C security architecture design and assessment" - provides guidance for formally modelling and designing cyber‑secure I&C architectures at nuclear power plants (NPPs). The technical report describes a model‑based approach to support plant‑specific risk assessment and to synthesize I&C architectures that meet cybersecurity requirements for safety‑critical systems.
Key Topics
- Integrated security modelling (ICM): guidance for creating a comprehensive security model that combines an information exchange model (DM) and a security model (SLM).
- Asset classification and clustering: formal techniques to rank, group and order I&C assets based on properties relevant to security.
- Security degree assignment: model‑based methods to assign security degrees to assets and to verify conformance between data flows and security requirements.
- Barrier measures and zone boundaries: assignment of protective measures and definition of security zones to contain threats and control information exchange.
- Information transfer requirements: specification of security requirements for data exchange between I&C components, operators and external systems.
- Secure‑by‑design principles: guidance to increase determinism in system designs to enhance cybersecurity in I&C architectures.
- Procedure and case study: step‑by‑step procedure for I&C security modelling, supported by a practical case study and algorithmic considerations (informative annexes).
- Simulation and assessment: concepts for using simulation (digital twin / stress tests) to validate and assess security architectures.
Applications
IEC TR 63415:2023 is intended to be used during the I&C system security life cycle to:
- Inform architecture synthesis for new or modified I&C systems.
- Support plant‑specific risk assessments by translating risk insights into modelled security requirements.
- Define secure information exchanges and map security requirements into the I&C design.
- Determine security zoning and protective measures based on formal analysis of assets and flows.
- Validate architecture changes through model analysis and simulation.
Who should use this standard
- I&C system architects and designers for NPPs
- Cybersecurity engineers and analysts working on nuclear I&C protection
- Safety and risk assessment teams performing plant‑specific evaluations
- Regulators and technical reviewers assessing I&C security architectures
Related standards
Use IEC TR 63415 alongside other IEC nuclear I&C and cybersecurity publications applicable to NPP instrumentation and control. Consult the IEC Webstore and committee TC45 guidance for complementary normative standards and implementation references.
Технические детали
- Технический комитет
- SC 45A - Instrumentation, control and electrical power systems of nuclear facilities
- SKU
- IEC TR 63415:2023
Похожие стандарты
Другие стандарты IEC
IEC 60050-161:1990/AMD2:1998
ДействующийAmendment 2 - International Electrotechnical Vocabulary (IEV) - Part 161: Electromagnetic compatibility
IEC 60050-161:1990/AMD2:1998 – Electromagnetic Compatibility Vocabulary Amendment ### Overview The IEC 60050-161:1990/AMD2:1998 is the second amendment to the International Electrotechnical Vocabular…