IEC-TR-62210-2003.pdf
《IEC-TR-62210-2003.pdf》由会员分享,可在线阅读,更多相关《IEC-TR-62210-2003.pdf(50页珍藏版)》请在三一文库上搜索。
1、TECHNICAL REPORT IEC TR 62210 First edition 2003-05 Power system control and associated communications Data and communication security Reference number IEC/TR 62210:2003(E) Copyright International Electrotechnical Commission Provided by IHS under license with IECLicensee=IHS Employees/1111111001, Us
2、er=Wing, Bernie Not for Resale, 03/09/2007 23:34:35 MSTNo reproduction or networking permitted without license from IHS -,-,- Publication numbering As from 1 January 1997 all IEC publications are issued with a designation in the 60000 series. For example, IEC 34-1 is now referred to as IEC 60034-1.
3、Consolidated editions The IEC is now publishing consolidated versions of its publications. For example, edition numbers 1.0, 1.1 and 1.2 refer, respectively, to the base publication, the base publication incorporating amendment 1 and the base publication incorporating amendments 1 and 2. Further inf
4、ormation on IEC publications The technical content of IEC publications is kept under constant review by the IEC, thus ensuring that the content reflects current technology. Information relating to this publication, including its validity, is available in the IEC Catalogue of publications (see below)
5、 in addition to new editions, amendments and corrigenda. Information on the subjects under consideration and work in progress undertaken by the technical committee which has prepared this publication, as well as the list of publications issued, is also available from the following: IEC Web Site (www
6、.iec.ch) Catalogue of IEC publications The on-line catalogue on the IEC web site (http:/www.iec.ch/searchpub/cur_fut.htm) enables you to search by a variety of criteria including text searches, technical committees and date of publication. On-line information is also available on recently issued pub
7、lications, withdrawn and replaced publications, as well as corrigenda. IEC Just Published This summary of recently issued publications (http:/www.iec.ch/online_news/ justpub/jp_entry.htm) is also available by email. Please contact the Customer Service Centre (see below) for further information. Cust
8、omer Service Centre If you have any questions regarding this publication or need further assistance, please contact the Customer Service Centre: Email: custserviec.ch Tel: +41 22 919 02 11 Fax: +41 22 919 03 00 Copyright International Electrotechnical Commission Provided by IHS under license with IE
9、CLicensee=IHS Employees/1111111001, User=Wing, Bernie Not for Resale, 03/09/2007 23:34:35 MSTNo reproduction or networking permitted without license from IHS -,-,- TECHNICAL REPORT IEC TR 62210 First edition 2003-05 Power system control and associated communications Data and communication security P
10、RICE CODE IEC 2003 Copyright - all rights reserved No part of this publication may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from the publisher. International Electrotechnical Commission, 3, ru
11、e de Varemb, PO Box 131, CH-1211 Geneva 20, Switzerland Telephone: +41 22 919 02 11 Telefax: +41 22 919 03 00 E-mail: inmailiec.ch Web: www.iec.ch X For price, see current catalogue Commission Electrotechnique Internationale International Electrotechnical Commission Copyright International Electrote
12、chnical Commission Provided by IHS under license with IECLicensee=IHS Employees/1111111001, User=Wing, Bernie Not for Resale, 03/09/2007 23:34:35 MSTNo reproduction or networking permitted without license from IHS -,-,- 2 TR 62210 IEC:2003(E) CONTENTS FOREWORD 4 1Scope and object. 5 2Overview . 5 3R
13、eference documents 6 4Terms, definitions and abbreviations 6 4.1Terms and definitions . 6 4.2Abbreviations.10 5Introduction to security11 5.1How to use this report11 6The security analysis process.12 6.1Network topologies 14 6.2User consequence based analysis.16 6.2.1Stakeholders16 6.3Consequences t
14、o be considered18 6.3.1Financial18 6.3.2Asset destruction/degradation19 6.3.3Inability to restore service20 6.4Consequences and security threats .20 7Focus of security work within this report .22 7.1Justification of application level security focus.22 7.2Security analysis technique .23 7.2.1Security
15、 objectives.23 7.2.2General threats24 7.2.3Specific threats to be considered in PP24 8Vulnerabilities.27 8.1Threats to topologies .27 8.2Current IEC Technical Committee 57 protocols29 8.2.1TASE.1 29 8.2.2TASE.2 30 8.2.3IEC 60870-5 30 8.2.4IEC 6133430 8.2.5IEC 6185031 9Recommendations for future IEC
16、Technical Committee 57 security work 32 Annex A (informative) What is a protection profile? 35 Annex B (informative) Protection profile for TASE.2 .37 Annex C (Informative) Example of consequence diagrams .43 Figure 1 Normal corporate security process .12 Figure 2 Business information flow.14 Figure
17、 3 General communication topology16 Figure 4 Consequence diagram: inability to restore service21 Copyright International Electrotechnical Commission Provided by IHS under license with IECLicensee=IHS Employees/1111111001, User=Wing, Bernie Not for Resale, 03/09/2007 23:34:35 MSTNo reproduction or ne
18、tworking permitted without license from IHS -,-,- TR 62210 IEC:2003(E) 3 Figure 5 WAN/LAN topology.27 Figure 6 Levels of vulnerability.28 Table 1 Matrix to determine business process importance17 Table 2 Asset to business process relationships 20 Table 3 Communication model security matrix22 Copyrig
19、ht International Electrotechnical Commission Provided by IHS under license with IECLicensee=IHS Employees/1111111001, User=Wing, Bernie Not for Resale, 03/09/2007 23:34:35 MSTNo reproduction or networking permitted without license from IHS -,-,- 4 TR 62210 IEC:2003(E) INTERNATIONAL ELECTROTECHNICAL
20、COMMISSION _ POWER SYSTEM CONTROL AND ASSOCIATED COMMUNICATIONS Data and communication security FOREWORD 1)The IEC (International Electrotechnical Commission) is a worldwide organization for standardization comprising all national electrotechnical committees (IEC National Committees). The object of
21、the IEC is to promote international co-operation on all questions concerning standardization in the electrical and electronic fields. To this end and in addition to other activities, the IEC publishes International Standards. Their preparation is entrusted to technical committees; any IEC National C
22、ommittee interested in the subject dealt with may participate in this preparatory work. International, governmental and non-governmental organizations liaising with the IEC also participate in this preparation. The IEC collaborates closely with the International Organization for Standardization (ISO
23、) in accordance with conditions determined by agreement between the two organizations. 2)The formal decisions or agreements of the IEC on technical matters express, as nearly as possible, an international consensus of opinion on the relevant subjects since each technical committee has representation
24、 from all interested National Committees. 3)The documents produced have the form of recommendations for international use and are published in the form of standards, technical specifications, technical reports or guides and they are accepted by the National Committees in that sense. 4)In order to pr
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- IEC TR 62210 2003
链接地址:https://www.31doc.com/p-3770520.html