Overview
ISO/TR 22100-4:2018 provides guidance for machine manufacturers on how related IT‑security (cyber security) aspects can influence the safety of machinery when a machine is placed on the market or put into service for the first time. It complements ISO 12100 by identifying IT‑security threats that could affect safety, outlining essential lifecycle steps and roles, and offering practical guidance for design choices, component selection and user documentation. This Technical Report is advisory - it does not prescribe detailed technical specifications nor does it cover physical bypass or defeat of protective measures.
Key topics
- Relationship to ISO 12100: Clarifies how traditional safety risk assessment (ISO 12100) differs from IT‑security risk assessment and why both must be considered.
- IT‑security vs safety objectives: Contrasts aims such as injury prevention with IT objectives (availability, integrity, confidentiality) and highlights differing dynamics and responsibilities.
- Threats, vulnerabilities and incidents: Defines key terms (attack, threat, vulnerability, IT‑security incident) and explains how these can impact machine control systems.
- Lifecycle approach: Recommends essential steps over the whole life cycle - from component selection and secure design to commissioning, maintenance and decommissioning.
- Practical guidance areas:
- Selection of hardware/software components with security in mind
- Secure machine design and control architecture
- Remote access management and authentication controls
- Instruction handbook content to inform users about IT‑security-related safety considerations
- Roles and responsibilities: Identifies manufacturers, integrators, service providers and users and their interaction on IT‑security tasks.
Applications and who uses it
ISO/TR 22100-4:2018 is intended for:
- Machine manufacturers designing safety‑critical machinery
- Safety and cybersecurity engineers who must bridge functional safety and IT‑security
- Integrators assembling manufacturing systems and defining interfaces
- Compliance and product managers preparing machines for market entry
Practical uses include developing secure machine control systems, specifying secure remote access, informing user manuals, and coordinating with integrators and service providers in smart manufacturing and industrial automation environments.
Related standards
- ISO 12100 - Safety of machinery: risk assessment and reduction (primary reference)
- IEC 62443 family - Industrial automation and control systems security (IT‑security risk assessment examples)
- ISO/IEC 20924 (IoT/smart manufacturing) and standards on machine control (e.g., ISO 13849) are referenced for contextual topics.
Keywords: ISO/TR 22100-4:2018, safety of machinery, IT-security, cyber security, risk assessment, machine control system, smart manufacturing, remote access, vulnerabilities.