Isa Iec 624
Isa Iec 624
Isa Iec 624
2
What is ISA 62443?
3
What is ISA 62443?
What is ISA 62443?
5
ISA/IEC 62443-1-1
Terminology,
Concepts and
Models
What is ISA 62443?
7
ISA/IEC 62443-2-1
Establishing an
Industrial Automation
and Control Systems
Security ISA/IEC 62443-2-1
Requirements for an
IACS Security
Management System
ISA/IEC 62443-2-3
Patch management in
the IACS
environment
What is ISA 62443?
10
ISA/IEC 62443-2-3
System security
requirements and
security levels
Real threats vs. Perceived threats
Potential cyber threats (What management
hears on the news or from IT)
• Database Injection
• Replay
• Spoofing
• Social Engineering
• Phishing
• Malicious Code
• Denial of Service
• Escalation of Privileges
Or the contractors
laptop
Your current likely cyber threats
• Establishing the criteria for identifying which devices comprise the IACS.
WAN
INTERNET
Remote PLC
Support via LOCAL ISP
Enterprise
Terminal
Services to
PLC Remote DCS
Engineering Support
Internal
Station (Static IP)
Device Adaptive Security
Firewall (Static IP) CEMS VIM CEMS Appliance and VPN
software System BUSINESS LAN
support support
(Static IP) (Static IP)
DMZ VLAN
CEMS PLC
DMZ
Engineering
Workstation
Station
I/P SWITCH
3
Fiber Optic 3 3
Channel B
DCS
Workstation virus/Management
Radio
(Password
1 2 1 2 1 2 DCS VLAN management)
1 2 1 2
1111 1 22222
1 2
Root Switch Root Switch Fiber Optic Channel A
(exisitng) (exisitng)
FIELD
Replace hub with optional switch to
create subnet to isolate HMI polls
from DCS network
31
Developing a network diagram of the IACS
32
Developing a network diagram of the IACS
WAN
INTERNET
Remote PLC
Support via LOCAL ISP
Enterprise
Terminal
Services to
PLC Remote DCS
Engineering Support
Internal
Station (Static IP)
Device Adaptive Security
Firewall (Static IP) CEMS VIM CEMS Appliance and VPN
software System BUSINESS LAN
support support
(Static IP) (Static IP)
DMZ VLAN
CEMS PLC
DMZ
Engineering
Workstation
Station
I/P SWITCH
3
Fiber Optic 3 3
Channel B
DCS
Workstation virus/Management
Radio
(Password
1 2 1 2 1 2 DCS VLAN management)
1 2 1 2
1111 1 22222
1 2
Root Switch Root Switch Fiber Optic Channel A
(exisitng) (exisitng)
FIELD
Replace hub with optional switch to
create subnet to isolate HMI polls
from DCS network