On October 9, 2017, Akademie Interne Revision GmbH will be holding a seminar in Vienna entitled “IT Security in Industry”. The seminar will also look at IEC 62443 and Security by Design, among other topics.
Seminar topic:
Terms such as Industry 4.0 or IoT stand for the dawn of a new age and the vision of end-to-end digitalization of all production processes. The networking of production and industrial plants and their IT components with office IT that is required for this means that the security risks already known from classic IT are also becoming increasingly important in this area. The use of industrial control systems in the area of critical infrastructures presents a particular challenge.
Responsibility for the security of the systems lies not only with the manufacturer, but the integrators and operators must also be held accountable. Overcoming these challenges requires a structured approach. “Security by design” is, however, an essential prerequisite here for the implementation of all further-reaching security measures. The IEC 62443 series of standards “Industrial communication networks — IT security for networks and systems” defines the “state of the art”, specifies the requirements and the procedure for securing production and industrial plants.
Target audience:
The seminar provides an overview of security risks and introduces IEC 62443 as a possible approach to securing. The primary target group are responsible and interested persons in the auditing department, the IT department, security officers but also managers and directors who want to learn about the risks and the possible solution approaches.
From the content (Standards — IEC 62443 — Security by Design):
- Initial situation
- General conditions
- Task of the revision
- Current threat situation (What do we have to protect ourselves from?)
- Basic concepts of information security
- Current threat situation (e.g. cyber attacks)
- Basic terms of IT and information security
- Standards and norms
- Structure of the IEC 64443 standards group
- Dealing with the product and system life cycle
- Risk assessment procedures
- What does “security by design” mean in the industrial environment?
- Requirements for manufacturers, integrators and operators
- Safety versus IT security
- Security levels according to IEC 62443
- Securing network transitions between office IT and plant networks
- Importance of network segmentation and security zones
- Security of remote maintenance access
- Structured approach to the development of security concepts
- Outlook on future developments
The seminar leader is Manfred Scholz. Questions about the seminar can be asked via the seminar organizer or via our contact form.
Further information about the seminar and registration link: Academy Internal Audit Seminarlink
Source: http://www.internerevision.at/