CAN/CSA-IEC/TR 62443-2-3:17
This part of IEC 62443, which is a Technical Report, describes requirements for asset owners
and industrial automation and control system (IACS) product suppliers that have established
and are now maintaining an IACS patch management program.
This Technical Report recommends a defined format for the distribution of information about
security patches from asset owners to IACS product suppliers, a definition of some of the
activities associated with the development of the patch information by IACS product suppliers
and deployment and installation of the patches by asset owners. The exchange format and
activities are defined for use in security related patches; however, it may also be applicable
for non-security related patches or updates.
The Technical Report does not differentiate between patches made available for the operating
systems (OSs), applications or devices. It does not differentiate between the product
suppliers that supply the infrastructure components or the IACS applications; it provides
guidance for all patches applicable to the IACS. Additionally, the type of patch can be for the
resolution of bugs, reliability issues, operability issues or security vulnerabilities.
NOTE 1 This Technical Report does not provide guidance on the ethics and approaches for the discovery and
disclosure of security vulnerabilities affecting IACS. This is a general issue outside the scope of this report.
NOTE 2 This Technical Report does not provide guidance on the mitigation of vulnerabilities in the period
between when the vulnerability is discovered and the date that the patch resolving the vulnerability is created. For
guidance on multiple countermeasures to mitigate security risks as part of an IACS security management system
(IACS-SMS), refer to, Annexes B.4.5, B.4.6 and B.8.5 in this Technical Report and other documents in the IEC
62443 series.
OEN:
CSA
Langue:
English
Code(s) de l'ICS:
25.040.40;
35.040;
35.100
Statut:
Norme
Date de Publication:
2017-09-30
Numéro Standard:
CAN/CSA-IEC/TR 62443-2-3:17