ISO/IEC TR 27019:2013 信息技术 安全技术 基于ISO/IEC 27002的能源公用事业特定的进程控制系统用信息安全管理指南
标准编号:ISO/IEC TR 27019:2013
中文名称:信息技术 安全技术 基于ISO/IEC 27002的能源公用事业特定的进程控制系统用信息安全管理指南
英文名称:Information technology — Security techniques — Information security management guidelines based on ISO/IEC 27002 for process control systems specific to the energy utility industry
发布日期:2013-07
标准范围
ISO/IEC/TR 27019:2013提供了基于ISO/IEC 27002的信息安全管理指导原则,适用于能源公用事业行业中使用的过程控制系统。ISO/IEC/TR 27019:2013的目标是将ISO/IEC 27000系列标准扩展到过程控制系统和自动化技术领域,从而使能源公用事业行业能够根据ISO/IEC 27001实施标准化信息安全管理系统(ISMS),该系统从业务扩展到过程控制层面。ISO/IEC/TR 27019:2013的范围涵盖了能源公用事业行业使用的过程控制系统,用于控制和监测电力、天然气和热能的产生、传输、储存和分配,以及支持过程的控制。这尤其包括以下系统、应用程序和组件:-整体IT支持中央和分布式过程控制、监控和自动化技术,以及用于其操作的IT系统,如编程和参数化设备;-数字控制器和自动化组件,如控制和现场设备或PLC,包括数字传感器和执行元件;-用于过程控制领域的所有进一步支持IT系统,例如用于辅助数据可视化任务,以及用于控制、监控、数据归档和文件编制目的;-过程控制领域使用的整体通信技术,例如网络、遥测、遥控应用和远程控制技术;-数字计量和测量装置,例如用于测量能耗、发电量或排放值;-数字保护和安全系统,例如保护继电器或安全PLC;-未来智能电网环境的分布式组件;-上述系统上安装的所有软件、固件和应用程序。不在ISO/IEC TR 27019:2013范围内的是非数字的传统或经典控制设备,即纯机电或电子监控和过程控制系统。此外,私人家庭和其他类似住宅建筑安装中的能源过程控制系统不在ISO/IEC/TR 27019:2013的范围内。过程控制环境中使用的电信系统和组件也不直接属于ISO/IEC/TR 27019:2013的范围。ISO/IEC 27011:2008涵盖了这些内容。
ISO/IEC/TR 27019:2013 provides guiding principles based on ISO/IEC 27002 for information security management applied to process control systems as used in the energy utility industry. The aim of ISO/IEC/TR 27019:2013 is to extend the ISO/IEC 27000 set of standards to the domain of process control systems and automation technology, thus allowing the energy utility industry to implement a standardized information security management system (ISMS) in accordance with ISO/IEC 27001 that extends from the business to the process control level.The scope of ISO/IEC/TR 27019:2013 covers process control systems used by the energy utility industry for controlling and monitoring the generation, transmission, storage and distribution of electric power, gas and heat in combination with the control of supporting processes. This includes in particular the following systems, applications and components:- the overall IT-supported central and distributed process control, monitoring and automation technology as well as IT systems used for their operation, such as programming and parameterization devices;- digital controllers and automation components such as control and field devices or PLCs, including digital sensor and actuator elements;- all further supporting IT systems used in the process control domain, e.g. for supplementary data visualization tasks and for controlling, monitoring, data archiving and documentation purposes;- the overall communications technology used in the process control domain, e.g. networks, telemetry, telecontrol applications and remote control technology;- digital metering and measurement devices, e.g. for measuring energy consumption, generation or emission values;- digital protection and safety systems, e.g. protection relays or safety PLCs;- distributed components of future smart grid environments;- all software, firmware and applications installed on above mentioned systems.Outside the scope of ISO/IEC TR 27019:2013 is the conventional or classic control equipment that is non-digital, i.e. purely electro-mechanical or electronic monitoring and process control systems. Furthermore, energy process control systems in private households and other, comparable residential building installations are outside the scope of ISO/IEC/TR 27019:2013.Telecommunication systems and components used in the process control environment are also not directly part of the scope of ISO/IEC/TR 27019:2013. These are covered by ISO/IEC 27011:2008.
标准预览图


