This report explores the use of the ISA/IEC 62443 series of standards for industrial automation and control systems (IACS) that include cloud-based functionality (i.e., industrial internet of things (IIoT)). The scope of an “IIoT IACS” includes all the systems and components necessary for a complete IACS including sensors, actuators and controllers at the edge, services in the cloud and the communications between edge and cloud.
This report is a companion to the “IIoT Component Certification Based on the 62443 Standard” study, which explores the use of ISA/IEC 62443-4-2, “Technical security requirements for IACS components” for IIoT components.
Section 4 is intended for the asset owner and covers risk assessment, role mapping, system under consideration, zone and conduit partitioning and 62443 scope. To explore these concepts, Annex A includes example risk assessments for four IIoT use cases:
- Example use case 1 – cloud-based data analytics – non-operational
- Example use case 2 – cloud-based data analytics – operational
- Example use case 3 – cloud-based operator view and manipulation
- Example use case 4 – cloud-based non-essential control
Section 5 explores potential improvement opportunities to facilitate the use of ISA/IEC 62443 for IIoT IACS. These recommendations are offered for consideration by ISA/IEC 62443 standards development organizations in the next editions of ISA/IEC 62443 standards, profiles and technical reports.
Section 6 explores the structure and organization of conformity assessment schemes (e.g., third-party certification) for IIoT systems and IACS. It is intended for organizations that are conformity assessment scheme owners such as the ISA Security Compliance Institute (ISASecure).
The main conclusions of this report include:
- The concepts in ISA/IEC 62443 standards can be applied to IACS that use cloud-based functionality. Concepts such as risk assessment, zone and conduit partitioning, and the system/component model can all be applied to an IIoT IACS.
- The scope of ISA/IEC 62443 should extend to the cloud environment when the cloud-based functionality has the capability to directly or indirectly change the physical state of the equipment under control.
- Implementation of essential functions in the cloud does not meet ISA/IEC 62443 requirements.
- This report proposes a new category of cloud service called operational technology as a service (OTaaS) to provide transparency when cloud-based functionality has the capability to directly or indirectly change the physical state of the equipment under control.
- The cloud provider is a new role not currently defined in the ISA/IEC 62443 series. The cloud provider role includes aspects of product supplier, service provider and asset owner (operator) roles.
- A comparison between ISA/IEC 62443 standards and the Cloud Security Alliance Cloud Controls Matrix v4 indicates that there may be some requirements that should be added to the ISA/IEC 62443 standards for the IIoT use case.
- Conformity assessment schemes (e.g., certification) could be developed for IIoT systems, components and IACS based on ISA/IEC 62443 standards, provided these standards are updated for the IIoT use case.
This report is not intended to encourage or dissuade the use of cloud-based functionality for industrial automation and control systems. The use of cloud-based functionality for IACS is a risk-based decision that is the responsibility of the asset owner.
Views: 134


















































