Overview
ISO/IEC 24392:2023 - Cybersecurity - Security reference model for industrial internet platform (SRM‑IIP) - is a first‑edition international standard that defines IIP‑specific security characteristics, threats, control objectives and recommended controls. It is designed to complement generic cybersecurity standards by addressing the particular needs of Industrial Internet Platforms (IIPs) that integrate industrial devices, edge computing, cloud infrastructure and multi‑stakeholder ecosystems. The standard helps organizations design, implement and manage security across the full IIP system life cycle (development, production, utilization/support, retirement).
Key topics and technical requirements
- IIP characteristics and threat analysis
- Identification of IIP‑specific threats arising from industrial processes, multi‑tenant platforms and cyber‑physical components.
- Security reference model and domains
- A domain‑based model covering edge security, cloud infrastructure security, platform security, application security and lifecycle considerations.
- System life cycle security
- Security requirements and guidance for development/production, operation/support and retirement stages.
- Security objectives and controls
- Context‑specific control objectives and recommended controls in areas such as:
- Physical security
- Network and communication security
- Access and authentication (including ABAC considerations)
- System and application security
- Operation, maintenance and security management
- Business scenarios and roles
- Guidance for production optimization, product customization, multilevel security production and transnational collaboration.
Practical applications and users
ISO/IEC 24392:2023 is intended for:
- Platform providers who develop or operate industrial internet platforms (IIPs)
- Manufacturers and industrial integrators deploying IIoT and cyber‑physical systems
- Cloud and edge service providers delivering infrastructure or managed services to industrial customers
- Third‑party vendors and service providers in the IIP supply chain
- Security architects and compliance teams seeking IIP‑specific controls
Typical uses:
- Designing secure data collection and transmission between industrial devices and the platform
- Hardening industrial cloud platforms and multi‑stakeholder collaboration interfaces
- Defining procurement, integration and lifecycle security requirements for IIoT and CPS components
- Aligning IIP security practices with enterprise risk management and regulatory needs
Related standards
ISO/IEC 24392:2023 complements and references generic and domain standards, e.g.:
Adopting ISO/IEC 24392:2023 helps organizations apply targeted cybersecurity controls for industrial internet platforms and bridge gaps between general IT security and industrial operational requirements.