首页 馆藏资源 舆情信息 标准服务 科研活动 关于我们
现行 BS PD IEC/TR 62443-2-3:2015
到馆提醒
收藏跟踪
购买正版
Security for industrial automation and control systems-Patch management in the IACS environment 工业自动化和控制系统的安全性
发布日期: 2015-07-31
BS PD IEC/TR 62443-2-3:2015是一份技术报告,描述了对资产所有者的要求 以及工业自动化和控制系统(IACS)产品供应商 现在正在维护一个IACS补丁管理程序。本技术报告建议采用一种已定义的格式来分发有关 从资产所有者到IACS产品供应商的安全补丁,这是一些 与IACS产品供应商开发补丁信息相关的活动 以及由资产所有者部署和安装补丁。交换格式和 定义了用于安全相关补丁的活动;然而,它也可能适用 用于非安全相关的修补程序或更新。技术报告没有区分为操作系统提供的补丁 系统(OSs)、应用程序或设备。它不区分产品 提供基础设施组件或IACS应用程序的供应商;它提供 适用于IACS的所有补丁的指南。此外,修补程序的类型可以是 解决缺陷、可靠性问题、可操作性问题或安全漏洞。注1:本技术报告不提供有关发现和试验的伦理和方法的指导 披露影响IAC的安全漏洞。这是本报告范围之外的一般性问题。注2:本技术报告不提供该期间漏洞缓解的指导 从发现漏洞到创建解决漏洞的修补程序的日期。 对于 作为IACS安全管理系统的一部分,关于缓解安全风险的多种对策的指南 (IACS-SMS),参考本技术报告附录B.4.5、B.4.6和B.8.5以及IEC中的其他文件 62443系列。交叉引用:IEC TS 62443-1-1IEC 62443-2-1IEC 62443-2-1IEC 62443-2-4IEC 62443-4-1ISO 639-1:2002ISO 3166-1:2006ISO 3166-2:2007ISO 4217:2008ISO 8601:2004ECE/TRADE/C/CEFACT/2009/24ECE/TRADE/C/CEFACT/2009/25购买本文件时可提供的所有现行修订版。
BS PD IEC/TR 62443-2-3:2015, which is a Technical Report, describes requirements for asset owners and industrial automation and control system (IACS) product suppliers that have established and are now maintaining an IACS patch management program.This Technical Report recommends a defined format for the distribution of information about security patches from asset owners to IACS product suppliers, a definition of some of the activities associated with the development of the patch information by IACS product suppliers and deployment and installation of the patches by asset owners. The exchange format and activities are defined for use in security related patches; however, it may also be applicable for non-security related patches or updates.The Technical Report does not differentiate between patches made available for the operating systems (OSs), applications or devices. It does not differentiate between the product suppliers that supply the infrastructure components or the IACS applications; it provides guidance for all patches applicable to the IACS. Additionally, the type of patch can be for the resolution of bugs, reliability issues, operability issues or security vulnerabilities.NOTE 1 This Technical Report does not provide guidance on the ethics and approaches for the discovery and disclosure of security vulnerabilities affecting IACS. This is a general issue outside the scope of this report.NOTE 2 This Technical Report does not provide guidance on the mitigation of vulnerabilities in the period between when the vulnerability is discovered and the date that the patch resolving the vulnerability is created. For guidance on multiple countermeasures to mitigate security risks as part of an IACS security management system (IACS-SMS), refer to, Annexes B.4.5, B.4.6 and B.8.5 in this Technical Report and other documents in the IEC 62443 series.Cross References:IEC TS 62443-1-1IEC 62443-2-1IEC 62443-2-1IEC 62443-2-4IEC 62443-4-1ISO 639-1:2002ISO 3166-1:2006ISO 3166-2:2007ISO 4217:2008ISO 8601:2004ECE/TRADE/C/CEFACT/2009/24ECE/TRADE/C/CEFACT/2009/25All current amendments available at time of purchase are included with the purchase of this document.
分类信息
发布单位或类别: 英国-英国标准学会
关联关系
研制信息
相似标准/计划/法规
现行
GB/T 42445-2023
工业自动化和控制系统安全 IACS环境下的补丁管理
Security for industrial automation and control systems—Patch management in the IACS environment
2023-03-17
现行
KS X IEC TR 62443-2-3
산업제어시스템 보안 — 제2-3부: IACS 환경의 패치 관리
工业自动化和控制系统的安全第2-3部分:IACS环境中的补丁管理
2023-11-17
现行
IEC TR 62443-2-3-2015
Security for industrial automation and control systems - Part 2-3: Patch management in the IACS environment
工业自动化和控制系统的安全.第2-3部分:IACS环境中的补丁管理
2015-06-30
现行
ISA 62443-2-1-2009
Security for Industrial Automation and Control Systems: Establishing an Industrial Automation and Control Systems Security Program
工业自动化和控制系统的安全:建立工业自动化和控制系统安全计划
2009-01-13
现行
BS EN IEC 62443-3-2-2020
Security for industrial automation and control systems-Security risk assessment for system design
工业自动化和控制系统的安全性
2020-09-04
现行
JB/T 11962-2014
工业通信网络 网络和系统安全 工业自动化和控制系统信息安全技术
Industrial communication networks-Network and system security-Security technologies for industrial automation and control systems
2014-05-12
现行
GB/T 40218-2021
工业通信网络 网络和系统安全 工业自动化和控制系统信息安全技术
Industrial commumication networks—Network and system security—Security technologies for industrial automation and control system
2021-05-21
现行
GB/T 33007-2016
工业通信网络 网络和系统安全 建立工业自动化和控制 系统安全程序
Industrial communication networks—Network and system security—Establishing an industrial automation and control system security program
2016-10-13
现行
BS EN 62443-2-1-2010
Industrial communication networks. Network and system security-Establishing an industrial automation and control system security program
工业通讯网络 网络与系统安全
2011-06-30
现行
BS EN IEC 62443-4-2-2019
Security for industrial automation and control systems-Technical security requirements for IACS components
工业自动化和控制系统的安全性
2019-05-07
现行
BS EN IEC 62443-4-1-2018
Security for industrial automation and control systems-Secure product development lifecycle requirements
工业自动化和控制系统的安全性
2018-04-13
现行
GB/T 42457-2023
工业自动化和控制系统信息安全 产品安全开发生命周期要求
Security for industrial automation and control systems—Secure product development lifecycle requirements
2023-03-17
现行
GB/T 42456-2023
工业自动化和控制系统信息安全 IACS组件的安全技术要求
Security for industrial automation and control systems—Technical security requirements for IACS components
2023-03-17
现行
ISA 62443-3-3(99.03.03)-2013
Security for industrial automation and control systems Part 3-3: System security requirements and security levels
工业自动化和控制系统的安全第3-3部分:系统安全要求和安全等级
2013-08-12
现行
BS EN IEC 62443-2-4-2019+A1-2019
Security for industrial automation and control systems-Security program requirements for IACS service providers
工业自动化和控制系统的安全性
2019-06-18
现行
GB/T 40682-2021
工业自动化和控制系统安全 IACS服务提供商的安全程序要求
Security for industrial automation and control system—Security program requirements for IACS service providers
2021-10-11
现行
KS X IEC TR 62443-3-1
산업 통신 네트워크 — 네트워크 및 시스템 보안 — 제3-1부: 산업제어시스템 보안기술
工业通信网络网络和系统安全第3-1部分:工业自动化和控制系统的安全技术
2023-11-17
现行
IEC TR 62443-3-1-2009
Industrial communication networks - Network and system security - Part 3-1: Security technologies for industrial automation and control systems
工业通信网络.网络和系统安全.第3-1部分:工业自动化和控制系统的安全技术
2009-07-30
现行
KS X IEC 62443-3-2
산업제어시스템 보안 — 제3-2부: 시스템 설계 보안 리스크 평가
工业自动化和控制系统的安全性.第3-2部分:系统设计的安全风险评估
2022-08-23
现行
IEC 62443-3-2-2020
Security for industrial automation and control systems - Part 3-2: Security risk assessment for system design
工业自动化和控制系统的安全.第3-2部分:系统设计的安全风险评估
2020-06-24