IEC TS 63383:2022 PDF
Cybersecurity aspects of devices used for power metering and monitoring, power quality monitoring, data collection and analysis
Cybersecurity aspects of devices used for power metering and monitoring, power quality monitoring, data collection and analysis
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 30
- Дата публикации:
- 23 ноября 2022 г.
- Издание:
- IEC TS 63383 edition 1 version 1
- ICS:
- 17.220.20
IEC TS 63383:2022 deals with cybersecurity related to measuring devices (PMD according to IEC 61557-12 and PQI according to IEC 62586-1) and devices for data collection (devices according to IEC 62974-1) that are intended to be installed in restricted access areas. This document deals with cybersecurity aspects (e.g. device hardening or device resilience) of device(s) used for power metering and monitoring, power quality monitoring, data collection and analysis, but does not cover requirements for organisational cybersecurity (e.g. end-user security policy). This document is a first attempt to develop awareness by manufacturers and other relevant stakeholders about cybersecurity aspects and provide basic guidance for achieving the appropriate security mitigation against vulnerabilities to security threats: – in coherence with device/system approaches described in relevant standards such as IEC 62443 (all parts) and ISO/IEC 27001, – based on generic system use-cases. This document does not cover billing meters covered by the IEC 62053-2x set of standards.
Abstract
Overview
IEC TS 63383:2022 provides guidance on cybersecurity aspects of devices used for power metering and monitoring, power quality monitoring, and data collection and analysis. It focuses on measuring devices (PMD per IEC 61557-12, PQI per IEC 62586-1) and data collection devices (per IEC 62974-1) intended for installation in restricted access areas. IEC TS 63383:2022 aims to raise manufacturer and stakeholder awareness of device-level cybersecurity (device hardening, resilience, risk mitigation) while excluding organisational cybersecurity policy and billing meters (IEC 62053-2x).
Key topics and technical requirements
The Technical Specification emphasises a risk-based approach and covers these core topics:
- Security objectives for device confidentiality, integrity and availability.
- Cybersecurity risk assessment methodology (generic approach, use-cases, metrics and prioritisation).
- Requirements for countermeasures (device hardening and mitigation strategies).
- Testing requirements for verifying security measures and device resilience.
- Lifecycle security management-design, manufacturing, commissioning, operation, maintenance, de‑commissioning and disposal.
- Instructions for use to support secure installation and operation.
- Informative annexes with generic risk assessments, device-feared events, attack vectors and example countermeasures for PMD, PQI, data gateways (DGW), energy data loggers (EDL) and energy servers (ESE).
Key concepts in the standard include attack vectors, device assets, and threat-driven prioritisation. The document aligns recommendations with system-level standards such as IEC 62443 and ISO/IEC 27001.
Applications and who should use it
IEC TS 63383:2022 is practical for stakeholders involved in the lifecycle of power-measurement and data-collection devices:
- Device manufacturers - to design and harden PMDs, PQIs, gateways and loggers against common vulnerabilities.
- System integrators and OEMs - for secure integration and commissioning of energy-monitoring systems.
- Facility managers and operators - to implement lifecycle security, maintenance and secure operational practices in restricted access areas.
- Test laboratories and cybersecurity assessors - to define test scopes and validation for device resilience.
- Product managers and compliance teams - to map device-level controls to organisational cybersecurity programs.
Related standards
- IEC 61557-12 (PMD definitions)
- IEC 62586-1 (PQI definitions)
- IEC 62974-1 (data collection devices)
- IEC 62443 (industrial automation and control system security)
- ISO/IEC 27001 (information security management)
IEC TS 63383:2022 is a targeted, risk-based reference for improving the cybersecurity posture of electrical measurement and data-collection devices used in energy systems.
Технические детали
- Технический комитет
- TC 85 - Measuring equipment for electrical and electromagnetic quantities
- SKU
- IEC TS 63383:2022
Похожие стандарты
Стандарты, упомянутые в описании
IEC 61557-12:2018/COR1:2022
ДействующийCorrigendum 1 - Electrical safety in low voltage distribution systems up to 1 000 V AC and 1 500 V DC - Equip…
IEC 62586-1:2017
ДействующийPower quality measurement in power supply systems - Part 1: Power quality instruments (PQI)
Overview IEC 62586-1:2017, titled Power Quality Measurement in Power Supply Systems – Part 1: Power Quality Instruments (PQI), is an internationally recognized standard developed by the International…
IEC 62974-1:2024
ДействующийMonitoring and measuring systems used for data collection, aggregation and analysis - Part 1: Device requirem…
Overview IEC 62974-1:2024 is the latest international standard established by the International Electrotechnical Commission (IEC) focusing on monitoring and measuring systems used for data collection…
IEC 62053-23:2003/AMD1:2016
ДействующийAmendment 1 - Electricity metering equipment (a.c.) - Particular requirements - Part 23: Static meters for re…
IEC 62443-4-2:2019/COR1:2022
ДействующийCorrigendum 1 - Security for industrial automation and control systems - Part 4-2: Technical security require…
ISO/IEC 27001:2022/Amd 1:2024
ДействующийInformation security, cybersecurity and privacy protection — Information security management systems — Requir…
Overview ISO/IEC 27001:2022/Amd 1:2024 is the latest amendment to the internationally recognized ISO/IEC 27001 standard, which establishes requirements for information security management systems (IS…