Industrial communication networks — Network and system security — Part 3-3: System security requirements and security levels

Logo
CSA Group
Standards Development Organisation:
Working Program:
Designation Number:
CAN/CSA-IEC 62443-3-3:17
Standard Type:
National Standard of Canada - Adoption of International Standard
Standard Development Activity:
Reaffirmation
ICS code(s):
25.040.40
35.110
Status:
Proceeding to development
SDO Comment Period Start Date:
SDO Comment Period End Date:
Posted On:

Scope:

Scope

This part of the IEC 62443 series provides detailed technical control system requirements (SRs) associated with the seven foundational requirements (FRs) described in IEC 62443?1?1 including defining the requirements for control system capability security levels, SL-C(control system). These requirements would be used by various members of the industrial automation and control system (IACS) community along with the defined zones and conduits for the system under consideration (SuC) while developing the appropriate control system target SL, SL-T(control system), for a specific asset. 

As defined in IEC 62443?1?1 there are a total of seven FRs: 
a) Identification and authentication control (IAC) 
b) Use control (UC) 
c) System integrity (SI) 
d) Data confidentiality (DC) 
e) Restricted data flow (RDF) 
f) Timely response to events (TRE), and 
g) Resource availability (RA). 

These seven requirements are the foundation for control system capability SLs, SL-C (control system). Defining security capability at the control system level is the goal and objective of this standard as opposed to target SLs, SL-T, or achieved SLs, SL-A, which are out of scope. 

See IEC 62443?2?1 for an equivalent set of non-technical, program-related, capability SRs necessary for fully achieving a control system target SL.

Project need:

Project Need
To review the Standard within the required 5 year period.

Note: The information provided above was obtained by the Standards Council of Canada (SCC) and is provided as part of a centralized, transparent notification system for new standards development. The system allows SCC-accredited Standards Development Organizations (SDOs), and members of the public, to be informed of new work in Canadian standards development, and allows SCC-accredited SDOs to identify and resolve potential duplication of standards and effort.

Individual SDOs are responsible for the content and accuracy of the information presented here. The text is presented in the language in which it was provided to SCC.