• PD IEC/TR 62443-2-3:2015

    Current The latest, up-to-date edition.

    Security for industrial automation and control systems Patch management in the IACS environment

    Available format(s):  Hardcopy, PDF

    Language(s):  English

    Published date:  31-07-2015

    Publisher:  British Standards Institution

    Add To Cart

    Table of Contents - (Show below) - (Hide below)

    FOREWORD
    INTRODUCTION
    1 Scope
    2 Normative references
    3 Terms, definitions, abbreviated terms and acronyms
    4 Industrial automation and control system patching
    5 Recommended requirements for asset owner
    6 Recommended requirements for IACS product supplier
    7 Exchanging patch information
    Annex A (informative) - VPC XSD file format
    Annex B (informative) - IACS asset owner guidance on patching
    Annex C (informative) - IACS product supplier/service provider
            guidance on patching
    Bibliography

    Abstract - (Show below) - (Hide below)

    Specifies requirements for asset owners and industrial automation and control system (IACS) product suppliers that have established and are now maintaining an IACS patch management program.

    Scope - (Show below) - (Hide below)

    This part of This part of IEC 62443 , which is a Technical Report, describes requirements for asset owners and industrial automation and control system (IACS) product suppliers that have established and are now maintaining an IACS patch management program. This Technical Report recommends a defined format for the distribution of information about security patches from asset owners to IACS product suppliers, a definition of some of the activities associated with the development of the patch information by IACS product suppliers and deployment and installation of the patches by asset owners. The exchange format and activities are defined for use in security related patches; however, it may also be applicable for non-security related patches or updates. The Technical Report does not differentiate between patches made available for the operating systems (OSs), applications or devices. It does not differentiate between the product suppliers that supply the infrastructure components or the IACS applications; it provides guidance for all patches applicable to the IACS. Additionally, the type of patch can be for the resolution of bugs, reliability issues, operability issues or security vulnerabilities. NOTE1 This Technical Report does not provide guidance on the ethics and approaches for the discovery and disclosure of security vulnerabilities affecting IACS. This is a general issue outside the scope of this report. NOTE2 This Technical Report does not provide guidance on the mitigation of vulnerabilities in the period between when the vulnerability is discovered and the date that the patch resolving the vulnerability is created. For guidance on multiple countermeasures to mitigate security risks as part of an IACS security management system (IACS-SMS), refer to, AnnexesB.4.5, B.4.6 and B.8.5 in this Technical Report and other documents in the IEC62443 series.

    General Product Information - (Show below) - (Hide below)

    Committee GEL/65
    Document Type Standard
    Publisher British Standards Institution
    Status Current

    Standards Referencing This Book - (Show below) - (Hide below)

    ISO 639-1:2002 Codes for the representation of names of languages — Part 1: Alpha-2 code
    IEC TS 62443-1-1:2009 Industrial communication networks - Network and system security - Part 1-1: Terminology, concepts and models
    IEC 62443-2-1:2010 Industrial communication networks - Network and system security - Part 2-1: Establishing an industrial automation and control system security program
    ISO 3166-2:2013 Codes for the representation of names of countries and their subdivisions Part 2: Country subdivision code
    ISO 8601:2004 Data elements and interchange formats Information interchange Representation of dates and times
    ISO 4217:2015 Codes for the representation of currencies
    ISO 3166-1:2013 Codes for the representation of names of countries and their subdivisions Part 1: Country codes
    • Access your standards online with a subscription

      Features

      • Simple online access to standards, technical information and regulations
      • Critical updates of standards and customisable alerts and notifications
      • Multi - user online standards collection: secure, flexibile and cost effective