Power systems management and associated information exchange. Data and communications security - Guidelines on security topics to be covered in standards and specifications

Power systems management and associated information exchange. Data and communications security - Guidelines on security topics to be covered in standards and specifications

Regular price
£272.00
Sale price
£272.00
Regular price
£136.00
Sold out
Unit price
per 

What is PD IEC/TR 62351-13- Data and communications security about? 

PD IEC/TR 62351-13 is a safety standard on power systems management and associated information exchange. 

PD IEC/TR 62351-13, which is a technical report, provides guidelines on what security topics could or should be covered in standards and specifications (IEC or otherwise) that are to be used in the power industry, and the audience is, therefore, the developers of standards and specifications. 

Note: Out-of-scope are explicit methods for cyber security in product development, implementations, or operations. 

Who is PD IEC/TR 62351-13- Data and communications security for?  

PD IEC/TR 62351-13 on data and communications security is relevant to: 

  • Information and communication technology (ICT) providers 
  • Security managers 
  • Testing and maintenance personnel 
  • Utility regulators 

Why should you use PD IEC/TR 62351-13- Data and communications security? 

PD IEC/TR 62351-13 provides guidelines on what security topics should be covered in standards and specifications (IEC or otherwise) that are to be used in the power industry. These guidelines cannot be prescriptive for every standard, since individual standards and specifications may legitimately have vastly different focuses, but it should be expected that the combination of such standards and specifications used in any implementation should cover these security topics. These guidelines are therefore to be used as a checklist for the combination of standards and specifications used in implementations of systems. 

The security requirements for human users and software applications are different from the purely technical security requirements found in many communication and device standards. 

For user security standards, more emphasis should be on “policy and procedures” and “roles and authorization” rather than “bits and bytes” cryptographic technologies that should be included in Information and Communications Technology (ICT). 

PD IEC/TR 62351-13 is structured into four sections: 

  • Clause 5: Security requirements for standards and specifications which do not address specific cybersecurity technologies but where interactions between human users, software applications, and smart devices should be secured 
  • Clause 6: Security requirements for standards and specifications that address information and communication technologies (ICT) 
  • Clause 7: Engineering design and configuration requirements that provide system reliability, defence-in-depth, and other security threat mitigations 
  • Clause 8: Security requirements related to the OSI reference model 

Overall, PD IEC/TR 62351-13 is helpful as it provides guidance on the security topics to be covered in standards and specifications for data and communications security.