Secure IACS by ISA-IEC 62443 Standard

所在平台: Udemy

课程主页: https://www.udemy.com/course/isa-iec-62443-standard-for-secure-iacs/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**课程名称:** 基于ISA-IEC 62443标准实现工控系统安全 (Secure IACS by ISA-IEC 62443 Standard) **课程概述:** 本课程介绍了ISA-IEC 62443标准的背景、重要性及安全性保障措施。起初,ISA99委员会旨在将IT标准应用于工控系统(IACS),但很快发现此举不足以确保IACS的安全性、完整性、可靠性和保密性。因此,国际自动化协会(ISA)和国际电工委员会(IEC)携手合作,共同致力于提升IACS的网络安全。 **为什么要保障工控系统安全?** 工控系统是物理与网络结合的系统,网络攻击可能带来严重后果,包括但不限于: * 危及公众或员工的生命安全与健康 * 对环境造成损害 * 损坏被控设备 * 导致产品完整性丧失 * 损害公众信任或公司声誉 * 违反法律法规要求 * 泄露专有或机密信息 * 造成财务损失 * 影响实体、地方、州或国家安全 **如何保障工控系统安全?** 课程重点介绍了保障工控系统安全的策略和方法,主要包括: * **风险评估 (Risk Assessment)** * **安全等级 (Security Level)** * **成熟度等级 (Maturity Level)** * **设计原则 (Design Principle)** 课程强调,**基础性要求 (Foundational Requirements, FRs)** 是ISA/IEC 62443系列技术要求的基础。为了达到期望的工控系统安全等级,需要满足与以下七项基础性要求相关的各项内容(涵盖人员、流程和技术): * **FR 1 - 身份识别与认证控制 (Identification and Authentication Control, IAC)** * **FR 2 - 使用控制 (Use Control, UC)** * **FR 3 - 系统完整性 (System Integrity, SI)** * **FR 4 - 数据保密性 (Data Confidentiality, DC)** * **FR 5 - 受限数据流 (Restricted Data Flow, RDF)** * **FR 6 - 事件及时响应 (Timely Response to Events, TRE)** * **FR 7 - 资源可用性 (Resource Availability, RA)**

课程评论(0条)

课程详情

What is ISA &IEC?Initially, the ISA99 committee considered IT standards and practices for use in the IACS. However, it was soon found that this was not sufficient to ensure the safety, integrity, reliability, and security of an IACS.The International Society of Automation (ISA) and the International Electrotechnical Commission (IEC) have joined forces to address the need to improve the cybersecurity of IACS.Why to Secure IACS?IACS are physical-cyber systems, the impact of a cyberattack could be severe. The consequences of a cyberattack on an IACS include, but are not limited to:Endangerment of public or employee safety or healthDamage to the environmentDamage to the Equipment Under ControlLoss of product integrityLoss of public confidence or company reputationViolation of legal or regulatory requirementsLoss of proprietary or confidential informationFinancial lossImpact on entity, local, state, or national securityHow to Secure IACS?Risk AssessmentSecurity LevelMaturity LevelDesign PrincipleFoundational Requirements (FRs) form the basis for technical requirements throughout theISA/IEC 62443 Series. All aspects associated with meeting a desired IACS security level (people, processes, and technology) are derived through meeting the requirements associated with theseven following Foundational Requirements:o FR 1 - Identification and Authentication Control (IAC)o FR 2 - Use Control (UC)o FR 3 - System Integrity (SI)o FR 4 - Data Confidentiality (DC)o FR 5 - Restricted Data Flow (RDF)o FR 6 - Timely Response to Events (TRE)o FR 7 - Resource Availability (RA)

课程标签

0人关注该课程

主题相关的课程