Cyber threats continue to bombard manufacturers– no matter the industrial sector. With threats becoming more sophisticated and the attack surface becoming larger, now is the time for engineers active in the creation, operation and maintenance of industrial automation and control systems (IACS) to strengthen their cybersecurity knowledge.
To that end, UL Solutions offers a 4-day course of OT-cybersecurity training heavily focused on the ISA/IEC 62443 series of standards developed to secure industrial automation and control systems. ISA/IEC 62443 series of standards helps inform asset owners/operators on securing IACS throughout their entire lifecycle.
This training includes several standards, technical reports (TR) and technical specifications (TS). During this interactive training, you will learn to make educated choices about the implementation of security based on the ISA/IEC 62443 series of standards.
This training has a core focus on the following ISA/IEC 62443 sub-standard most relevant to IACS asset owners:
- 2-1: Security program requirements for IACS Asset Owners
The course will cover an overview of all the following sub-standards and explore how they apply to asset owners in defining their roadmap for processes and system integration, system design, assessment and certification needs and required investment:
- 2-3: Patch management in the IACS environment
- 2-4: Security program requirements for IACS service providers
- 3-1: Security technologies for industrial automation and control systems
- 3-2: Security risk assessment for system design
- 3-3: System security requirements and security levels
- 4-1: Secure product development lifecycle requirements
- 4-2: Technical security requirements for IACS components
- ISO-27xxx: Information Technology – Security Techniques – Information Security Management Systems (only relevant parts for operational technology (OT) cybersecurity)
Additionally, the course provides an overview of the IACS lifecycle. It reviews cybersecurity risk assessment, developing zones and conduits, cybersecurity requirements definition, evaluation and profiles, designing secure systems, security and maturity level definition and application, design concepts, operations requirements, security monitoring and incident response, and maintenance of cybersecurity countermeasures executed in the implementation phase.