Design Con 2015
Breaking News
Comments
Newest First | Oldest First | Threaded View
CMathas
User Rank
Manager
Re: Any examples...
CMathas   9/9/2013 9:15:21 AM
NO RATINGS
The focus of this standard is how to set up a cyber security management program. The ANSI/ISA-62443-3-3 standard is the first standard from ISA-99 which provides technical cyber security standards for the control systems that make up an IACS—the first standard to address systems.

While there are several industry-segmented standard covering water, infrastructure, oil and gas, etc., cyber security is left to the user to implement. Sometimes that's not possible as the systems aren't capable of meeting the requirements of the individual standards. ANSI/ISA-62443-3-3 defines these capabilities. End users can now define compliance to the ANSI/ISA-62443-3-3 standard as their requirement in their procurement specification. Naturally, issues of cyber security and implementation continue to evolve—somewhat rapidly, so there is a futures element of this. Like several standards, however, a basis of certification from which to go forward is always preferable compared with everyone to their own devices. This certification is currently ISASecure, from the ISA Security Compliance Institute (ICSI). Now, with the new standard, certification for these systems will be labeled ISASecure SSA. Systems that have been designed for this level of security will be easily identified.

As to a specific future vulnerability on a system level, there are so many current ones with systems the constant target of hacking, and nothing sufficient in place to protect so many, I think the criminal mind would be better than mine to think of a future vulnerability! Hacking and undermining are constantly evolving.

Thanks for posting, Charles.

 

Charles.Desassure
User Rank
Manager
Any examples...
Charles.Desassure   9/7/2013 12:36:40 AM
NO RATINGS
This sounds very interesting.  After doing additional research,  according to the International Electrotechnical Commission (IEC), this standard is designed to provide a flexible framework to address and mitigate current and future vulnerabilities in industrial automation and control systems (IACS).  I wonder if they could provide and example of a future vulnerability in this area.  Carolyn Mathas, any examples?



Most Recent Comments
Flash Poll
Top Comments of the Week
Like Us on Facebook
EE Times on Twitter
EE Times Twitter Feed

Datasheets.com Parts Search

185 million searchable parts
(please enter a part number or hit search to begin)
EE Life
Frankenstein's Fix, Teardowns, Sideshows, Design Contests, Reader Content & More
Max Maxfield

Are Today's Designs Bound by the Constraints of Yesteryear?
Max Maxfield
26 comments
As part of my ongoing Pedagogical and Phantasmagorical Inamorata Prognostication Engine project (try saying that 10 times quickly), I'm working with Jason Dueck from Instrument Meter ...

Jolt Judges and Andrew Binstock

Jolt Awards: The Best Books
Jolt Judges and Andrew Binstock
1 Comment
As we do every year, Dr. Dobb's recognizes the best books of the last 12 months via the Jolt Awards -- our cycle of product awards given out every two months in each of six categories. No ...

Engineering Investigations

Air Conditioner Falls From Window, Still Works
Engineering Investigations
2 comments
It's autumn in New England. The leaves are turning to red, orange, and gold, my roses are in their second bloom, and it's time to remove the air conditioner from the window. On September ...

David Blaza

The Other Tesla
David Blaza
5 comments
I find myself going to Kickstarter and Indiegogo on a regular basis these days because they have become real innovation marketplaces. As far as I'm concerned, this is where a lot of cool ...