Posts

Showing posts with the label 2018 at 08:06AM

Cyber-nationalism in Cybersecurity Standards

Image
There are a variety of global standards that have been created to provide guidance to Industrial Control System (ICS) vendors and end users attempting to secure systems.  Examples include ISA/IEC 62443, and ISO/IEC 15408.  Many countries are utilizing these globally accepted standards to define ICS cybersecurity requirements.  Several countries have begun to create independent cybersecurity requirements.  Some examples include: China – GB/T 22239 defines cybersecurity requirements for critical infrastructure. Russia – The Russian federation has defined FSTEK Order 31 and 187-FZ cybersecurity regulations. US – The US has not defined country specific requirements, but has created standards for specific industrial segments. NERC-CIP for example is applicable electrical utilities.  NIST standards provide cybersecurity guidance, but are not required. Europe – The European Union is in the process of defining cybersecurity requirements through the ENISA age...