<?xml version="1.0" encoding="utf-8"?>
<Spec id="310" path="\a\2\a2dd499d6f2774a5ce1e25ba2350a180.pdf"><Text id="48479" page="5">Requirements: Industrial Automation and Control Systems Network Classification: Internal</Text><Text id="48480" page="5">according to IEC 62264-1:2013-05 clause 5.2.1, also known as the Purdue Architecture for IACS&quot;. The different levels can be seen in figure 1 below. Note the locations of the firewalls, and that it is generally permitted for control and service traffic to share the same physical network where necessary.</Text><Text id="48481" page="5">The document also states some common requirements to computers used for engineering and monitoring purposes. This to ensure we utilize shared resources where applicable, increased standardization and simplify operation/maintenance of the equipment.</Text><Text id="48482" page="5">Please note that additional requirements may apply as specified in other discipline technical requirement documents.</Text><Text id="48496" page="6">If connectivity is needed between HIPPS/FWP/EmG to ensure monitoring and possible remote this may be solved by a control mechanism in a conduit.</Text><Text id="48497" page="6">SR-77134 - The IACS networks shall support integrated security concepts as defined by TR1658.</Text><Text id="48498" page="6">SR-86592 - The IACS network design shall safeguard aspects for facility operation, system independence, system performance and technology used.</Text><Text id="48499" page="6">SR-86591 - Effort shall be made to share infrastructure within the individual physical infrastructures where possible based on risk assessments done. Requirements to the following needs to be maintained in the design:</Text><Text id="48501" page="6">SR-76647 - Separate network management solutions customized to Company operational model shall be designed for:</Text><Text id="48506" page="6">SR-86589 - The high availability networks design shall be limited to use the following network protocols in accordance with IEC 62439:</Text><Text id="48507" page="6">• Parallel Redundancy Protocol (PRP) when zero fail over time is required</Text><Text id="48508" page="6">• High-availability Seamless Redundancy (HSR) when zero fail over time is required</Text><Text id="48509" page="6">SR-86756 - RSTP shall not be used as a network redundancy protocol in high availability networks, but may be used to add redundancy to equipment connection on edge switch ports.</Text><Text id="48510" page="6">SR-92089 - Network edge switch ports (where Devices or Computers are connected) shall have BPDU guard enabled.</Text><Text id="48511" page="6">SR-86588 - The networks shall have a high availability design when the data communicated is critical for safety or production, or if the connected networked component requires a high availability data link.</Text><Text id="48512" page="6">SR-86587 - The networks shall have capacity to handle the data load for all operational modes. SR-77150 - The IACS networks shall be scalable with respect to capability and capacity. SR-77160 - The IACS networks shall be based on recognised open industry standards. SR-77459 - The IACS networks shall support Quality of Service (QoS) functionality. SR-86585 - The networks shall support Virtual Local Area Network (VLAN) functionality.</Text><Text id="48513" page="6">SR-77669 - The IACS networks shall prioritise IACS dependent data traffic over non-dependent data traffic if deployed on a shared physical network infrastructure.</Text><Text id="48514" page="6">SR-86586 - The IACS networks design shall protect the networked components from unwanted network traffic where</Text><Text id="48515" page="6">relevant. SR-77163 - The IACS networks shall be able to distribute time to networked components. SR-77648 - Time in redundant network configurations shall be sourced from redundant Real Time Clocks. SR-77133 - The IACS networks shall support end-to-end connectivity for management data where required.</Text><Text id="48518" page="7">SR-79218 - The network IP plan shall be pre-approved by Company.</Text><Text id="48519" page="7">SR-78009 - Computers, except server hardware used for virtual hosts, shall not be connected to different networks by- passing installed firewalls.</Text><Text id="48520" page="7">SR-91917 - Server hardware used for virtual hosts shall not be connected across different Purdue levels.</Text><Text id="48521" page="7">SR-86593 - If encrypted data links are used between networks on different levels, the traffic shall be decrypted before entering end-point firewalls with DPI and IDS enabled.</Text><Text id="48522" page="7">SR-86697 - The IACS systems shall be designed so that the use of (Supplier) laptops and similar portable computers is not required for configuration, operation or maintenance.</Text><Text id="48523" page="7">SR-86696 - Software applications necessary for maintenance, configuration and parameterisation of the IACS systems shall be included and installed on Engineering work stations.</Text><Text id="48524" page="7">SR-76646 - Data links shall be identified and classified in accordance with its consequence for facility safety, information security and production.</Text><Text id="48525" page="7">The framework described in NOG 123 can be used for this assessment.</Text><Text id="48526" page="7">SR-77911 - Cyber Security Risk assessment for the System under Consideration (SuC, ref TR1658) shall be done to identify the network infrastructure to be utilized.</Text><Text id="48528" page="7">SR-86613 - Systems critical for facility safety or production shall not be dependent of the Level 3 Technical network to execute its function.</Text><Text id="48529" page="7">SR-86612 - The Level 3 Technical core network layer shall have a fault tolerant design.</Text><Text id="48530" page="7">A Level 3 Technical distribution network layer should be used where there is a need for aggregating network layers and provide unique connectivity services within a distribution network segment.</Text><Text id="48531" page="7">SR-86617 - The Level 3 Technical network shall provide distribution, policy control, and isolation points between the network segment and the rest of the IACS networks.</Text><Text id="48532" page="7">SR-86616 - The Level 3 Technical network shall have a fault tolerant design towards the core or distribution network.</Text><Text id="48533" page="7">SR-86615 - The Level 3 Technical network shall be connected to a high availability firewall solution in the Company secure access solution for secure data traffic within and to/from the network.</Text><Text id="48534" page="7">SR-77773 - The Level 3 Technical network components shall be compatible and integrated with Company centralised</Text><Text id="48536" page="8">SR-86626 - The Level 2 SAS control edge switches shall have a high availability design towards the core network.</Text><Text id="48539" page="8">SR-86620 - Systems critical for facility safety or production shall not be dependent of the Level 2 Technical network to execute its function.</Text><Text id="48540" page="8">SR-86619 - The Level 2 Technical core network layer shall have a fault tolerant design.</Text><Text id="48541" page="8">A Level 2 Technical distribution network layer should be used where there is a need for aggregating network layers and provide unique connectivity services within a distribution network segment.</Text><Text id="48542" page="8">SR-86623 - The Level 2 Technical network shall have a fault tolerant design towards the core or distribution network.</Text><Text id="48543" page="8">SR-86622 - The Level 2 Technical network shall have a high availability firewall solution installed to restrict data traffic within and to/from the network.</Text><Text id="48545" page="8">SR-86636 - Systems critical for facility safety or production shall not be dependent of the Level 3 SAS network to execute its function.</Text><Text id="48546" page="8">SR-86635 - The Level 3 SAS core network layer shall have a fault tolerant design.</Text><Text id="48547" page="8">SR-86634 - The Level 3 SAS network shall provide distribution, policy control, and isolation points between the network segment and the rest of the network.</Text><Text id="48548" page="8">SR-86633 - The Level 3 SAS network shall have a fault tolerant design towards the core network.</Text><Text id="48549" page="8">SR-86632 - The Level 3 SAS network shall have a high availability firewall solution installed for secure data traffic within and to/from the network.</Text><Text id="48551" page="8">SR-86631 - The Level 2 SAS HMI core network layer shall have a high availability design. SR-86627 - The Level 2 SAS HMI edge switches shall have a high availability design towards the core network.</Text><Text id="48552" page="8">The Level 2 SAS control networks should be used for controller to controller data traffic and to provide network connection to solutions in the Level 2 SAS network and Level 1 SAS field networks.</Text><Text id="48553" page="8">SR-86625 - The Level 2 SAS control core network layer shall have a high availability design.</Text><Text id="48554" page="9">SR-77672 - PRP field networks shall have a dual star design as indicated in the figure below.</Text><Text id="48557" page="9">SR-86639 - The Level 1 SAS field networks layer shall have a high availability design.</Text><Text id="48558" page="9">SR-86644 - A SAS Level 1 field distribution network layer shall be used where there is a need for aggregating network layers and provide unique connectivity services within a distribution network segment.</Text><Text id="48559" page="9">SR-86643 - Where independent A and B cable routing is required, separate Level 1 SAS core network switches shall be used.</Text><Text id="48560" page="9">SR-86642 - The Level 1 SAS PCS field networks shall have a redundant firewall solution installed for enabling secure data links between the field devices and the management solutions.</Text><Text id="48561" page="9">SR-86687 -The level 1 IEC 61850 network shall use PRP, specified in Clause 4 of IEC 62439-3:2012, both for Station Bus and (if implemented) Process Bus.</Text><Text id="48564" page="9">SR-78573 - Non-SAS logic solvers in Class 2 packages, which use the field network to communicate to e.g. MCCs, shall have separate VLANs for this purpose.</Text><Text id="48565" page="9">SR-78572 - Level 2 Technical network traffic shall be in separate VLANs to the SAS VLANs, where the device supports this.</Text><Text id="48569" page="9">Figure 2 Diagram showing principle of locating the two PRP hubs physically separate</Text><Text id="48570" page="9">SR-78496 - Devices and computers which does not support PRP shall be connected using a redbox. SR-78494 - Devices and computers shall be connected to a port on a switch.</Text><Text id="48571" page="9">SR-78553 - If the SAS logic solver does not support PRP, one redbox shall be used for connecting PRP A and PRP B to the SAS A network, and another redbox shall be used for similar connection to the SAS B network.</Text><Text id="48572" page="9">SR-78551 - Communication to Level 2 Technical network shall be done through a separate redbox.</Text><Text id="48587" page="11">Control system Control system Note: both PRP A and B (orange and green) and redundant A and B (red and blue) are available to suit the control system.</Text><Text id="48589" page="11">PRP A net PRP B net SAS A net SAS B net Service net</Text><Text id="48590" page="11">SR-78030 - Software licenses shall be registered to Company and activated before project handover to operation.</Text><Text id="48592" page="11">HV Switchboard A HV Switchboard B MV Switchboards A MV Switchboards B LV Switchboard A LV Switchboard B</Text><Text id="48593" page="11">Figure 4 Principle drawing for IEC61850 station bus network topology using PRP</Text><Text id="48594" page="11">lEDs should connect to the network using PRP, without the use of a redbox. SR-78543 - Switches used in IEC 61850 networks shall not enable write MMS support. SR-78542 - Where PTP is required, switches used in IEC 61850 networks shall support PTP.</Text><Text id="48596" page="11">SR-83693 - The agreed official software version for all software components shall be available for installation before project handover to operation.</Text><Text id="48597" page="11">SR-83695 - All agreed official software patches shall be installed before project handover to operation. SR-83692 - The operating system shall be of Long-term Support (LTS) version where available.</Text><Text id="48602" page="12">SR-78482 - The network and networked equipment shall provide data for inventory, backup status, health and performance.</Text><Text id="48603" page="12">Use of staging should be considered to avoid unnecessary exposure to external networks.</Text><Text id="48604" page="12">SR-81821 - The message log monitoring software and protocols shall be based on recognised open standards.</Text><Text id="48605" page="12">SR-78484 - The facility shall have a message log monitoring solution for capture and storage of message logs from all networked IACS.</Text><Text id="48606" page="12">SR-78477 - The message log monitoring solution shall provide a secure interface for communicating message log data to other Company systems.</Text><Text id="48607" page="12">SR-78478 - The message log monitoring solution shall be able to save all messages to files on a Company file share.</Text><Text id="48608" page="12">SR-78464 - The message log monitoring solution shall include a historian module for capturing and storing time stamped equipment data.</Text><Text id="48609" page="12">SR-78470 - The message log monitoring solution shall as a minimum provide the following information:</Text><Text id="48615" page="12">SR-81838 - The management software shall include a module for capturing changes to the hardware configuration, back- up the configurations and ability to load them to the hardware component.</Text><Text id="48616" page="12">SR-81837 - It shall be possible to recover configuration data on the management software from backups.</Text><Text id="48618" page="13">Requirements: Industrial Automation and Control Systems Network Classification: Internal</Text><Text id="48620" page="13">SR-86601 - The system shall support different levels of user access rights to prevent unauthorised access to system and application software.</Text><Text id="48621" page="13">SR-86600 - The system shall have a role-based access allowing assignment of users/user groups to roles.</Text><Text id="48622" page="13">SR-86599 - It shall be possible to configure the access roles to limited parts of the system and/or limited parts of the application software.</Text><Text id="48623" page="13">SR-86598 - The identity and access management software shall include functionality for cyber security controls including audit controls. As a minimum the following are to be included:</Text><Text id="48627" page="13">SR-86605 - The project shall in due time get a final acceptance from Company on the network equipment and computer hardware standardisation chosen.</Text><Text id="48628" page="13">SR-79188 - Replacement of redundant hardware components shall be possible during normal operation, without any loss of functionality or production.</Text><Text id="48629" page="13">SR-86604 - The network equipment and networked computers shall be able to export message logs including alarm and events (security events included).</Text><Text id="48630" page="13">SR-86603 - The networked components shall support connectivity without need of extensive manual integration services. SR-86608 - The networked components shall communicate by the use of Ethernet. SR-86607 - All unused communication ports on network equipment and networked components shall be locked, disabled or protected by software means. If not possible through software, a physical port lock product shall be used.</Text><Text id="48631" page="13">SR-86606 - The network equipment and networked components shall handle wire-speed network storms gracefully, i.e. network port may be shut down temporarily but shall automatically be re-enabled when the storm has ended.</Text><Text id="48633" page="13">SR-86699 - Devices with a Ethernet service port; these shall be connected to the network. SR-78500 - Devices with a serial/USB service port; these shall be connected to the network using a serial/IP server.</Text><Text id="48634" page="13">It is not necessary to connect multiple service ports if the functionality is already taken care of for the device.</Text><Text id="48635" page="13">SR-78501 - Devices with only one network interface shall support both control and service traffic.</Text><Text id="48636" page="14">solution, including a HMI panel from the user&apos;s work desk, for open/close of predefined firewall rulesets.</Text><Text id="48639" page="14">5.2 Standardisation The network equipment for use in protected area should be from one manufacturer and of the same product family. The network equipment for use outside protected area should be from one manufacturer and of the same product family. SR-79191 - The client hardware shall be from one manufacturer and of the same product family within a system. SR-79186 - The server hardware shall be from one manufacturer and of the same product family within a system.</Text><Text id="48640" page="14">SR-86610 - The network equipment and computer hardware shall be commercial of the shelf products that are suitable for its intended use.</Text><Text id="48642" page="14">SR-79207 - The network equipment used in the core or distribution networks shall have minimum 1 Gigabit/s bandwidth on uplinks and edge ports.</Text><Text id="48643" page="14">SR-79210 - The network equipment shall be able to be managed from the management software.</Text><Text id="48644" page="14">SR-79212 - The network equipment shall do automatic startup with correct configuration without any user intervention after loss of power.</Text><Text id="48645" page="14">SR-79209 - The network equipment’s configuration shall be available for online or offline upload after replacement of component.</Text><Text id="48646" page="14">SR-81377 - Where redbox functionality is needed; the edge switch shall support redbox functionality.</Text><Text id="48648" page="14">SR-78021 - The main firewall solutions at Level 3 Technical network, Level 3 SAS Technical network and Level 2 Technical network shall be redundant firewall cluster solutions with state synchronisation that support Deep Package Inspection (DPI) and Intrusion Detection System (IDS).</Text><Text id="48649" page="14">SR-84565 - The management interface of the firewalls shall be protected. SR-86649 - The main firewall at Level 2 Technical network shall be integrated with an independent managed barrier</Text><Text id="48650" page="15">SR-92429 - Virtual hardware allocation shall be in accordance to actual needs and have the capacity to handle predicted</Text><Text id="48652" page="15">SR-77781 - Server hardware with server operating system shall be used as run-time environment when Level 2 or Level 3 application software demands for 24x7 operation.</Text><Text id="48653" page="15">SR-77780 - Server hardware shall run a virtualisation environment. SR-78010 - Server hardware shall include a dedicated out-of-band management interface. SR-79217 - The server hardware shall have rack or DIN rail mount.</Text><Text id="48654" page="15">SR-79216 - The server hardware shall be fault tolerant against disk failures and with automatic online recovery when replacing a disk.</Text><Text id="48655" page="15">SR-79215 - The internal power supplies and fans in the server hardware shall be active redundant. SR-78032 - All application software with a demand for 24x7 operation installed in the server shall run as a service in the background, independently whether interface user is logged in or out to the applications.</Text><Text id="48658" page="15">SR-77782 - Clients shall run as bare metal installation, no virtualisation required.</Text><Text id="48659" page="15">The client hardware may be removed if the system solves the same with a virtual computer as part of a Server hardware.</Text><Text id="48661" page="15">SR-78012 - A dedicated physical network port shall be used in the server hardware for connecting the Hypervisor management interface to the relevant management system.</Text><Text id="48662" page="15">SR-92430 - If a Hypervisor cluster is installed for redundancy, redundancy on management shall be implemented according to best practice from the applicable Hypervisor vendor.</Text><Text id="48663" page="15">SR-78008 - Virtual machines shall be supplied in Open Virtualization Format (OVF) if the virtual machine is to be implemented on a Hypervisor from another delivery.</Text><Text id="48664" page="15">SR-78007 - All virtual disks shall be thick provisioned Lazy zeroed. Thick provisioned Eager zeroed virtual disks may be used if vendor application requires it.</Text><Text id="48665" page="16">procedure for update and scanning shall be made and executed.</Text><Text id="48668" page="16">SR-78023 - The provisioning of the new device shall be done using applications on the EWS.</Text><Text id="48669" page="16">SR-78027 - The provisioning procedure shall include enabling of ports, configuring IP addresses and other details necessary for the new device to be inserted into the network and receive its main configuration from the EWS.</Text><Text id="48670" page="16">SR-78026 - Initial configuration using a network cable shall be preferred over USB.</Text><Text id="48672" page="16">SR-78033 - Larger infrastructures (e.g. SAS) shall provide their own internal backup solution which may utilize the shared facility solution for offline backup.</Text><Text id="48673" page="16">SR-78036 - To reduce the amount of data being synchronized to onshore centralized storage for offsite backup, systems shall use block level backup rotation when offline backup is copied to the shared facility solution.</Text><Text id="48674" page="16">SR-79219 - The components configuration shall be available for online or offline upload after replacement of equipment.</Text><Text id="48677" page="16">SR-78786 - To ensure the integrity of the delivered system before connecting it to the network a Cyber Security</Text><Text id="48698" page="18">A conduit can be a single service (i.e., a single Ethernet network) or can be made up of multiple data carriers (multiple network cables and direct physical accesses). As with zones, it can be made of both physical and logical constructs. Conduits may connect entities within a zone or may connect different zones.</Text><Text id="48699" page="18">As with zones, conduits may be either trusted or untrusted. Conduits that do not cross zone boundaries are typically trusted by the communicating processes within the zone. Trusted conduits crossing zone boundaries must use an end-to- end secure process.</Text><Text id="48700" page="18">Untrusted conduits are those that are not at the same level of security as the zone endpoint. In this case the security of the communication becomes the responsibility of the individual channel. Further information on this scenario is available in the Annex.</Text><Text id="48701" page="18">A conduit regulates communication between one or more devices in the same security zone or different security zones. A conduit within a security zone could be the control center LAN. A conduit between two zones could be the WAN connection between the primary and backup control centers. Conduits can be trusted or untrusted. Each conduit is assigned a security level.</Text><Text id="48702" page="18">Data Representation of facts, concepts, or instructions in a manner suitable for communication, interpretation, or processing by humans or by automatic means. (Source: ISO/IEC/IEEE 24765:2017).</Text><Text id="48703" page="18">Data link Means of connecting one networked device to another for the purpose of transmitting and receiving digital information.</Text><Text id="48704" page="18">Devices Devices, also referred to as “Embedded Devices”, are components such as (but not limited to) PLCs, VSD controllers, Motor starters, Thyristor controllers, Flow computers, lEDs, Serial servers, Communication devices, Advanced analysers etc.</Text><Text id="48705" page="18">A “Device” is basically any configurable I programmable Component which is not considered a “Computer” or “Network Equipment”.</Text><Text id="48706" page="18">Note that Windows CE (Compact Embedded), or Windows loT Core, are not considered general-purpose Operating Systems. Components running these operating systems (typically local HMI Panels) are considered “Devices”.</Text><Text id="48707" page="18">Distribution network layer The distribution layer aggregates the uplinks from the edge (also called access) layer to the core network layer. See &quot;Network distribution switch&quot;.</Text><Text id="48708" page="18">End user In product development, an end user (sometimes end-user) is a person who ultimately uses or is intended to ultimately use a product. The end user stands in contrast to users who support or maintain the product.</Text><Text id="48709" page="18">Engineering Work Station The maintenance stations for industrial control systems where system management and application software engineering,</Text><Text id="48712" page="18">Firewall A network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. A firewall typically establishes a barrier between a trusted internal network and untrusted external network. (Source; Wikipedia)</Text><Text id="48714" page="19">High Availability A characteristic of a system, which aims to ensure an agreed level of operational performance, usually uptime, for a higher than normal period. (Source; Wikipedia)</Text><Text id="48715" page="19">Human-Machine Interface (HMI) Provides the physical interface between technical systems and the personnel operating and maintaining the production facility, e.g. operator stations, large screen displays, critical action panels present in control rooms, local control panels and engineering work stations.</Text><Text id="48716" page="19">Hypervisor A hypervisor is a computer software, firmware or hardware that creates and runs virtual machines. A computer on which a hypervisor runs one or more virtual machines is called a host machine, and each virtual machine is called a guest machine. The hypervisor presents the guest operating systems with a virtual operating platform and manages the execution of the guest operating systems. Multiple instances of a variety of operating systems may share the virtualized hardware resources. (Source; Wikipedia)</Text><Text id="48717" page="19">Intelligent electronic device (IED) Microprocessor-based controllers of power system equipment, such as circuit breakers, transformers and capacitor banks. lEDs receive data from sensors and power equipment and can issue control commands, such as tripping circuit breakers if they sense voltage, current, or frequency anomalies, or raise/lower voltage levels in order to maintain the desired level.</Text><Text id="48718" page="19">May Indicates a course of action permissible within the limits of the document. (Source: Company Management system)</Text><Text id="48719" page="19">Network equipment Electronic devices which are required for communication and interaction between devices on a computer network, also known as Networking hardware, e.g. switches, firewalls, routers, etc. (Source; Wikipedia)</Text><Text id="48720" page="19">Network equipment management Services provided include fault analysis, performance management, provisioning of networks/network equipment and maintaining quality of service.</Text><Text id="48721" page="19">Network core switch A core switch is a high-capacity switch generally positioned within the backbone or physical core of a network. Core switches provide the final aggregation point for the network and allow multiple aggregation modules to work together. The core is designed to be highly reliable and stable to aggregate all the elements in the operational facility, typically Layer 3 (ISO/IEC 7498) devices, with high speed connectivity, redundant links, and redundant hardware.</Text><Text id="48722" page="19">Network distribution switch The distribution layer in provides policy-based connectivity and demarcation between the access layer and the core layer. In small-to-medium size networks, it is possible to collapse the core into the distribution switches.</Text><Text id="48723" page="19">Network edge switch The edge switch (also called access switch) provides the demarcation between the network infrastructure and the devices</Text><Text id="48724" page="19">that leverage that infrastructure. As such, it provides a security, QoS, and policy trust boundary. When looking at the overall IACS network design, the edge switch provides the majority of these access layer services and is a key element in enabling multiple IACS network services.</Text><Text id="48725" page="19">Network message log server In computing, a log file is a file that records either events that occur in an operating system or other software runs, or</Text><Text id="48727" page="20">messages between different users of a communication software. Logging is the act of keeping a log. In the simplest case, messages are written to a single log file. Many operating systems, software frameworks and programs include a logging system. A widely used logging standard is syslog. The Network message log server provides storage of syslog messages I SNMP traps with functionality like forwarding, filtering, analysis etc.</Text><Text id="48728" page="20">Network Time Protocol (NTP) Protocol used to synchronize clocks throughout a computer network, defined in RFC documents. The current protocol is version 4 (NTPv4), which is a proposed standard as documented in RFC 5905. It is backward compatible with version 3, specified in RFC 1305.</Text><Text id="48729" page="20">Operator station HMI equipment where the operator can perform control and monitoring. One or more operator stations will form an operator workplace.</Text><Text id="48730" page="20">Protected area This term is used to address location of non-explosion protected safety critical equipment such that the probability of gas exposure to ignition sources or damage is as low as reasonably practicable. Such equipment will be protected long enough to carry out safety functions. Such locations should be in the accommodation or in utility area close to the accommodation area. Probability for exposure of equipment within the enclosure to gas releases at 20% LEL, typically 10-4 per year or less. Special provisions, e.g. gas detection and means for isolating ignition sources, may be required. (Source: TR1055 v9.0)</Text><Text id="48731" page="20">Precision Time Protocol (PTP) Protocol used to synchronize clocks throughout a computer network, defined in IEEE 1588 v2.</Text><Text id="48732" page="20">Quality of Service (QoS) QoS refers to traffic prioritization and resource reservation control mechanisms rather than the achieved service quality. QoS is the ability to provide different priority to different applications, users, or data flows, or to guarantee a certain level</Text><Text id="48733" page="20">of performance to a data flow. (Source; Wikipedia)</Text><Text id="48734" page="20">Short form for Redundant Box. A network switch with PRP functionality, used in IEC 61850 networks, for connecting single attached devices to a PRP network.</Text><Text id="48735" page="20">Redundancy The presence of auxiliary equipment in a system to perform the same or similar functions as other elements for the purpose of preventing or recovering from failures. (Source: ISO/IEC/IEEE 24765:2017)</Text><Text id="48736" page="20">Real Time Clock (RTC) A computer clock (most often in the form of an integrated circuit) that keeps track of the current time. (Soruce; Wikipedia)</Text><Text id="48737" page="20">SAS Control class 2 Control and/or monitoring functions are partially integrated into SAS. Non-SAS control equipment are either directly connected to SAS network or interfaced to other SAS equipment via communication link. Systems and equipment under control are operated and monitored through SAS HMI following SAS HMI standard for uniform operation.</Text><Text id="48738" page="20">SAS Control class 3 Control and monitoring functions are not integrated in SAS. No interface to SAS is required, however supervisory control</Text><Text id="48740" page="20">or monitoring from SAS HMI could be applied. Systems and equipment under control are operated and monitored through stand-alone HMI.</Text><Text id="48741" page="20">Scalability The degree to which a system can have its capacities adjusted to meet system requirements. (Source: O-PAS™ Standard - Glossary and Abbreviations:2019)</Text><Text id="48758" page="22">message is labeled with a facility code, indicating the software type generating the message, and assigned a severity level. May be uses for system management and security auditing as well as general informational, analysis, and debugging messages.</Text><Text id="48759" page="22">System A set of elements and of relations between the elements such that the set may be looked at as a whole. (Source: ISO 5127/1)</Text><Text id="48760" page="22">System under Consideration (SuC) System Under Consideration. IEC62443 term.</Text><Text id="48761" page="22">Thick provisioning In virtual storage, thick provisioning is a type of storage allocation in which the amount of storage capacity on a disk is pre-allocated on physical storage at the time the disk is created.</Text><Text id="48762" page="22">Variabel Speed Drive (VSD) A type of adjustable-speed drive used in electro-mechanical drive systems to control AC motor speed and torque by varying motor input frequency and voltage. (Source; Wikipedia)</Text><Text id="48764" page="22">Requirements: Industrial Automation and Control Systems Network Classification: Internal</Text><Text id="48765" page="22">Zone A security zone is a logical grouping of physical, informational, and application assets sharing common security requirements.</Text><Text id="48767" page="22">A security zone has a border, which is the boundary between included and excluded elements. Zones may be considered to be trusted or untrusted. The standard requires a minimum of three security levels for security zones: high, medium and low. Other Parts of the IEC62443 standard will define administrative and technical requirements for these security levels.</Text><Text id="48768" page="22">cc Control Class CPU Central Processing Unit EmG Emergency Generator EPU Equipment Package Unit EWS Engineering Work Station FW Firewall FWP Firewater Pump HMI Human Machine Interface IACS Industrial Automation and Control System IED Intelligent Electronic Device IP Internet Protocol MMS Manufacturing Message Specification NTP Network Time Protocol PCS Process Control System PRP Parallel Redundancy Protocol PTP Precision Time Protocol QoS Quality of Service RTC Real Time Clock SAS Safety and Automation System</Text><Text id="48771" page="23">VLAN Virtual Local Area Network VSD Variabel Speed Drive</Text></Spec>