Enhancing Power Generation Security - Interpreting ISA/IEC 62443 Standards
Andrew Ginter
The #1 most widely-read author in the industrial security space | VP Industrial Security | Podcast Host | Author| MS, CISSP, ISP, ITCP
This week, Dr. Jesus Molina is spotlighting practical, industry-specific guidance for applying the broad ISA/IEC 62443 standards to safeguard critical power infrastructure.
Jesus Molina is a former hacker, his research on offensive security in industrial systems has been echoed by many publications and media, including Wired and NPR.
Additionally, Dr. Jesus Molina will be hosing a free webinar "Industry-Specific 62443 Insights for Power Generation" - September 18th at 11am EST.
Why Another Guide on 62443??
The ISA/IEC 62443 standards offer comprehensive guidance on securing Operational Technology (OT) systems, yet applying these standards to the power generation sector can be challenging. Because of these needs, we thought a comprehensive guide and focused webinar was needed on how these standards can be tailored specifically for power generation, making them more effective and easier to implement.??
Understanding the 62443 Standards…but with Power Generation in Mind?
The ISA/IEC 62443 standards are globally recognized as essential for enhancing OT security across various industries. However, the standards are designed to be horizontal, meaning they apply broadly across industries without specific guidance for verticals like power generation. This flexibility can create complexity, especially when deciding how to apply risk assessments, zoning requirements, and controls in a power plant environment.?
Recently, various industries have recognized the need for more tailored guidance within the 62443 framework. The rail sector, for example, has developed Technical Specification 50701 (TS-50701), which is evolving into the IEC 62451 standard, to address cybersecurity challenges unique to rail systems.??
领英推荐
Guidance Focus??
This is a no-nonsense guide designed to help you confidently create a program based on 62443, tailored specifically to the needs of power generation. We will cover the following topics, among others:?
The Goal: A Modern Cybersecurity Program for Power Generation?
Applying the 62443 standards to power generation involves more than just following the guidelines. It requires a modern, engineering-driven cybersecurity assessment that prioritizes synchronization with engineering teams. This approach ensures that cybersecurity is integrated into the engineering process from the outset, rather than being treated as an afterthought.?
As technology and threats evolve, so must our approach to cybersecurity. The integration of cloud technologies, the rise of Zero Trust models, and the need for remote access are just a few of the modern challenges that power generation facilities must address.?
The yet to be released eBook and upcoming webinar aim to do just that: interpret a great standard like 62443 to help create a better, modern, and focused cybersecurity program for power generation.?
Click here to register for the webinar September 18th at 11am EST - Industry-Specific 62443 Insights for Power Generation
OT/ICS Cybersecurity Analyst - Cisco CyberOps Associate | CompTIA Sec+ | Splunk | QRadar | CrowdStrike | SentinelOne | Proof-point | Nessus | Jira | ServiceNow | TheHive
1 个月@ Dr. Jesus Molina, is there a recording for the webinar: Industry-Specific 62443 Insights for Power Generation?
Founder & CEO at Talentedge | Data-Driven HR Strategist | Tech Industry VP HR
6 个月Interesting event
The only easy day was yesterday.
6 个月One small correction: The CENELEC TS 50701 is evolving into the IEC 63452 standard (not 62451). Best regards from the railway sector.
Security Solutions Architect ICS OT at Waterfall Security Solutions | Expert in Safe OT to IT Integration
6 个月I'm really looking forward to the webinar.
OT Cybersecurity Thought Leader | Protecting Critical Infrastructure | University Lecturer
6 个月Thank you for featuring this article Andrew, I hope your audience finds the information useful. My goal for the upcoming webinar and ebook is to provide guidance that reduces complexity while improving the resilience of power generation systems by addressing events that could produce unacceptable consequences from the onset. This is achieved through a consequence-based risk assessment, creating zones according to that assessment, and mitigating these events using engineered controls. Residual risks are then evaluated and mitigated using 62443, NERC CIP and other power-generation-specific advice. Your readers can find more information about the webinar here - https://hubs.li/Q02NGzyW0