IEC TR 62443-2-3:2015
IEC TR 62443-2-3:2015

IEC TR 62443-2-3:2015

July 2015
Technical report Current

Security for industrial automation and control systems - Part 2-3: Patch management in the IACS environment

IEC TR 62443-2-3:2015(E) describes requirements for asset owners and industrial automation and control system (IACS) product suppliers that have established and are now maintaining an IACS patch management program. This Technical Report recommends a defined format for the distribution of information about security patches from asset owners to IACS product suppliers, a definition of some of the activities associated with the development of the patch information by IACS product suppliers and deployment and installation of the patches by asset owners. The exchange format and activities are defined for use in security related patches; however, it may also be applicable for non-security related patches or updates.

Main informations

Collections

International IEC standards

Publication date

July 2015

Number of pages

61 p.

Reference

IEC TR 62443-2-3:2015

ICS Codes

25.040.40   Industrial process measurement and control
35.040.40   Coding of audio, video, multimedia and hypermedia information
35.100.05   Multilayer applications

Print number

1
Sumary
Security for industrial automation and control systems - Part 2-3: Patch management in the IACS environment

IEC TR 62443-2-3:2015(E) describes requirements for asset owners and industrial automation and control system (IACS) product suppliers that have established and are now maintaining an IACS patch management program. This Technical Report recommends a defined format for the distribution of information about security patches from asset owners to IACS product suppliers, a definition of some of the activities associated with the development of the patch information by IACS product suppliers and deployment and installation of the patches by asset owners. The exchange format and activities are defined for use in security related patches; however, it may also be applicable for non-security related patches or updates.
ZOOM ON ... the Requirements department

To comply with a standard, you need to quickly understand its issues in order to determine its impact on your activity.

The Requirements department helps you quickly locate within the normative text:

  • mandatory clauses to satisfy,
  • non-essential but useful clauses to know, such as permissions and recommendations.

The identification of these types of clauses is based on the document "ISO/IEC Directives, Part 2 - Principles and rules of structure and drafting of ISO documents" as well as on a constantly enriched list of verbal forms.

With Requirements, quickly access the main part of the normative text!


Need to identify, monitor and decipher standards?