Course Introduction
From manufacturing and processing plants to energy suppliers and railways, industries are implementing cyber-physical systems, which can improve efficiency while gaining unparalleled flexibility and innovating business models. However, with the increase in cyber attacks, new interconnectivity also brings changes in the risk landscape. In this context, suppliers and system integrators must optimize the cyber resilience of their components and systems by improving their development, integration and support processes. To reduce risks in industrial communication networks, the international standard IEC 62443 provides a structural method for industrial information security. The standard was originally developed for the supply chain of industrial automation and control systems, and has now become an industrial cybersecurity standard commonly adopted by various factories, facilities and systems in various industries, applicable to component suppliers, system integrators and asset owners. IEC 62443-4-1 specifies process requirements for secure development of products used in industrial automation and control systems, defining a Secure Development Lifecycle (SDL) for developing and maintaining secure products. This lifecycle includes security requirement definition, security design, secure implementation (including coding guidelines), verification and validation, defect management, patch management and product end-of-life. This course will comprehensively interpret the clauses of the IEC 62443-4-1 standard. Learners will learn basic knowledge of industrial cybersecurity and understand basic requirements for information security in product development preparation. This course does not require learners to have prior basic security knowledge.
Training Benefits
- Understand basic safety knowledge of IEC 62443-4-1
- Understand basic requirements of industrial information security involved in basic product components
- By communicating current threats and attack vectors, establish product threat models and improve industrial cybersecurity awareness
- Through basic requirements and frameworks of product safety design, establish product safety foundations and maturity levels
- Prepare products for passing security testing itself
Target Participants
- Operations managers, project and production managers, IT managers, product developers and designers
Course Outline
- What is the IEC 62443 standard
- Subdivisions of the IEC 62443 standard
- Introduction to component product maturity levels
- Introduction to component product functional safety levels
- Security requirement definition
- Security design, secure implementation, verification and validation
- Defect management
- Patch management
- Case analysis
- Information security risk assessment