Implementing Cybersecurity for Industrial-Connected Products
Nathan Laan, Rahul Gupta, Alexander W. Koehler, Wesley Van Hill · 2024
This paper provides an overview of current cybersecurity standards. It presents a case study on applying cybersecurity standards, practices, and certifications to a cybersecurity program covering a range of industrial-connected products. It reflects on where the industry is regarding cybersecurity risk — highlighting current standards and certification programs and looking at upcoming standards and the regulations related to them.As part of the overview of cybersecurity standards, this paper examines current and upcoming region-specific requirements, the complexities this cause, efforts to harmonize relevant standards, and how to best focus on meeting those requirements as a global manufacturer. Particular attention is paid to the requirements of the International Society of Automation (ISA) / International Electrotechnical Commission (IEC) 62443 (within the framework of National Institute of Standards and Technology (NIST) SP 800-53) and the specific obligations that need to be met by component and equipment manufacturers.The case study examines how manufacturers can use certifications to minimize risk by demonstrating alignment with security best practices and standards. It also reflects on how to use a certification program to help manufacturers streamline compliance burdens while meeting customers’ needs, concentrating on the significant challenges, strategies for implementation and how the certification bodies involved in these regulations can assist in overcoming those challenges through training and awareness.