On November 22, 2018, Manfred Scholz will lead a seminar entitled “IT Security in Industry” at the Institute for Internal Auditing Austria in Vienna. Special focus will be the IEC 62443 series of standards defining the state of the art in industry.
Terms such as Industry 4.0 or IoT stand for the dawn of a new age and the vision of end-to-end digitization of all production processes. The networking of production and industrial plants and their IT components with office IT that is required for this means that the security risks already known from classic IT are also becoming increasingly important in this area. The use of industrial control systems in the area of critical infrastructures presents a particular challenge.
Responsibility for the security of the systems lies not only with the manufacturer, but the integrators and operators must also be held accountable. Overcoming these challenges requires a structured approach. “Security by design” is, however, an essential prerequisite here for the implementation of all further-reaching security measures. The IEC 62443 series of standards “Industrial communication networks — IT security for networks and systems” defines the “state of the art”, specifies the requirements and the procedure for securing production and industrial plants.
Target group
The seminar provides an overview of security risks and introduces IEC 62443 as a possible approach to securing. Primary target group are responsible and interested persons in the revision, the IT department, security officers but also executives and managing directors who want to inform themselves about the risks and the possible solution approaches.
Methodology
- Lecture
- practical case studies
- Discussion
Seminar contents
- INTRODUCTION
- Initial situation
- General conditions
- Task of the audit
- Current threat situation (e.g. cyber attacks)
- Basic concepts of IT and information security
- Standards and norms
- Structure of the IEC 64443 standards group
- Dealing with the product and system life cycle
- Risk assessment procedures
- What does “security by design” mean in the industrial environment?
- Requirements for manufacturers, integrators and operators
- Safety versus IT security
- Security levels according to IEC 62443
- Securing network transitions between office IT and plant networks
- Importance of network segmentation and security zones
- Security of remote maintenance access
- Structured approach to the development of security concepts
- Outlook on future developments
Speaker:
Manfred Scholz
Managing Director SEC4YOU
Direct contact
Follow-up to further information on IEC 62443
Link: Registration