Example: confidence

IEC62443の概要と認証について - css-center.or.jp

Control System Security Center 1 iec62443 Control System Security Center CSSC CSSC 2013 11 20 EDSA : Embedded Device Security Assurance Control System Security Center 1. 2. 3. iec62443 2 Control System Security Center 3 Control System Security Center 4 Stuxnet( Web o 05/4 Control System Security Center Stuxnet Stuxnet 2009 2010 9000 1000 Stuxnet ---- 5 Control System Security Center)

Control System Security Center 1 IEC62443の概要と認証について 技術研究組合制御システムセキュリティセンター Control System Security Center CSSC

Tags:

  Iec62443

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of IEC62443の概要と認証について - css-center.or.jp

1 Control System Security Center 1 iec62443 Control System Security Center CSSC CSSC 2013 11 20 EDSA : Embedded Device Security Assurance Control System Security Center 1. 2. 3. iec62443 2 Control System Security Center 3 Control System Security Center 4 Stuxnet( Web o 05/4 Control System Security Center Stuxnet Stuxnet 2009 2010 9000 1000 Stuxnet ---- 5 Control System Security Center)

2 FA PA SCADA DCS Controller Historical Data Server PLC 4 20ma Field bus RS232c / Ethernet SCADA DCS Operation Terminal VEC TCP/IP) 6 Control System Security Center ICS-CERT 2009 ICS-CERT (2010 2013 ) ICS-CERT ICSJWG2013 Fall (2013 ) ICS CERT Industrial Control Systems Cyber Emergency Response Team 7 Stuxnet 0501001502002503002010 2013 2012 2011 ICS-CERT Monitor Newsletters April-June 2013 ICSJWG Control System Security Center 8 DSD, NIST Whitelisting) word OS Continuous Monitoring SIEM 75 DSD: Defense Signals Directorate Control System Security Center CSSC: Control System Security Center 9 Control System Security Center CSSC 2011 2012 2010 2013 (CSSC) 2012/3/6 2011/10 2012/4 2010/12 2011/8 CSS-Base6 ( 2014- CSSC CSS-Base6) 2013.

3 EDSA CSSC CSMS JIPDEC/IPA 10 Control System Security Center 2012 3 CSSC 1. 2. 3. ( 11 Control System Security Center CSSC Control System Security Center CSSC 50 21 2013 11 * 8 * * * IT * * * * * 2012 3 6 (TTHQ) 3-4-1 F-21 6 ( ))

4 JPCERT (TRC) 2-4-7 8 12 Control System Security Center CSSC 13 20130801 Control System Security Center CSSC 14 Control System Security Center 15 CSS-Base6 7 2013 5

5 7 Control System Security Center iec62443 16 ISA International Society of Automation ISAS ecure : ISCI ISA Security Compliance Institute EDSA : Embedded Device Security Assurance Control System Security Center iec62443 ISCI WIB iec62443 IEC 62443 IEC61850 ISCI WIB NERC CIP IEEE1686 NIST IR7628 ISO/IEC 62278 ISCI: ISA Security Compliance Institute WIB: International Instrument User s Association 17 CSMS SSA Control System Security Center iec62443 -4 iec62443 -3 iec62443 -1 iec62443 -2 *1) iec62443 Cyber security IEC/TC65/WG10 ( JEMIMA ) *2) EDSA Embedded Device Security Assurance ( ) iec62443 -4 *3) WIB: International Instrument User s Association iec62443 -2-4 DCS: Distributed Control System PLC: Programmable Logic Controller PIMS: Process Information Management System ISCI.

6 ISAS eure EDSA *2) *1) M PLCHMIPLCPIMS DCS/Slave EWSDCS/Master iec62443 / EDSA ) iec62443 iec62443 18 WIB*3) Control System Security Center iec62443 CSMS EDSA Cyber Security Management System) Embedded Device Security Assurance 19 12 3 EDSA CSMS Control System Security Center TUViT Trusted Site Security SCADA Infrastructure WIB(International Instrument Users Association) Wurldtech Achilles ISA ISCI ISCI(ISA Security Compliance Institute) ISAS ecure EDSA iec62443 ( Embedded Device Security Assurance ) 20 Control System Security Center ISA Security Compliance Institute (ISCI) ISA Automation Standards Compliance Institute(ASCI) 2007 ISA Security Compliance Institute (ISCI)

7 And ISAS ecure 21 Control System Security Center 22 ISCI Strategic Member Chevron ExxonMobil Honeywell Invensys Siemens Yokogawa Voting 50000 Technical Member Exida RTP Corporation Voting 5000 25000 Associate Member Voting 5000 Government Member IPA Voting 5000 Information Member Egemin Voting 1500 SSA System Security Assurance EDSA CSSC SSA CSSC ISCI Control System Security Center 23 ISCI ISAS ecure ISAS ecure EDSA ( ) ISCI ISAS ecure ISAS ecure System Security Assurance (SSA) ISAS ecure Embedded Device Security Assurance (EDSA) ISAS ecure Security Development Lifecycle Assurance (SDLA) SSA SDLA ISCI ISA Security Compliance Institute ISA International Society of Automation PCLS: Provisional Chartered Laboratory Status ISA99 62443(= iec62443 ) ISAS ecure ISAS ecure 3 EDSA Control System Security Center EDSA 24 EDSA.

8 Programmable Logic Controller (PLC) Distributed Control System (DCS) controller Safety Logic Solver Programmable Automation Controller (PAC) Intelligent Electronic Device (IED) Digital Protective Relay Smart Motor Starter/Controller SCADA Controller Remote Terminal Unit (RTU) Turbine controller Vibration monitoring controller Compressor controller ISA Security Compliance Institute (ISCI) and ISAS ecure 24 Control System Security Center 25 Certification Scheme(EDSA-100)Chartered lab operations and accreditation(EDSA-200)CRT tool recognition(EDSA-201)ISAS ecurecertification requirements(EDSA-300)Maintenance of ISAS ecurecertification(EDSA-301)CRT(EDSA-310 )FSA(EDSA-311)SDSA(EDSA-312)Ethernet(EDS A-401)ARP(EDSA-402)IPv4(EDSA-403)ICMPv4( EDSA-404)UDP(EDSA-405)TCP(EDSA-406) EDSA IPA EDSA ISCI Control System Security Center EDSA EDSA (SDSA) (FSA) (CRT) (robust) , 3 / 3 ( ) SDSA FSA CRT ISA Security Compliance Institute (ISCI) and ISAS ecure EDSA : Embedded Device Security Assurance Communication Robustness Testing CRT), Functional Security Assessment(FSA), Software Development Security Assessment SDSA) 26 Control System Security Center (SDSA).

9 Set of requirements, derived from existing reference standards and traceable to source standard (IEC 61508, ISO/IEC 15408) SDSA ISO/IEC 15408-1 I5408-3 IT Part1 Part3 IEC 61508 Part 3 / / ICSJWG Spring 2011, (ASCI) Validating the Security Assurance of Industrial Automation Products 27 Control System Security Center SDSA This phase specifies a process for planning and managing security development activities to ensure that security is designed into a product. For example, this phase incorporates requirements that the development team have a security management plan and that the developers assigned to the project are competent and have been provided basic training in good security engineering practices and processes. Also includes requirements that the project team creates and follows a configuration management plan.

10 Most vulnerabilities and weaknesses in software intensive information systems can be traced to inadequate or incomplete requirements. This phase requires that the project team document customer driven security requirements, security features and the potential threats that drive the need for these features. Software architecture facilitates communication between stakeholders, documents early decisions about high-level design, and allows reuse of design components and patterns between projects. This phase requires the project team develop a top-level software design and ensures that security is included in the design. This phase requires the project team determine which components can affect security and plan which components will require security code reviews and security testing. Also requires that a threat model be created and documented for the product. This phase requires the project team design the software down to the module level following security design best practices.


Related search queries