<?xml version="1.0" encoding="utf-8"?>
<Spec id="329" path="\e\f\ef7d00843b51fe519fb2d1316619862d.pdf"><Text id="54210" page="14">SR-79186 - The server hardware shall be from one manufacturer and of the same product family within a system.</Text><Text id="56255" page="1">Requirements: Industrial Automation and Control Systems Network Classification: Internal</Text><Text id="56256" page="1">&amp;38$5ÿ&apos;51ÿ&quot;14# !715ÿ&quot;657ÿ5#4ÿ$54%4 ÿÿ ÿ ÿ ÿ ÿ ÿ</Text><Text id="56261" page="2">Page 2 of 23 ÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿ</Text><Text id="56263" page="2">ÿÿÿ ÿ ÿÿ ÿÿÿ ÿ ÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ</Text><Text id="56264" page="2">ÿ ÿÿÿÿÿ ÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿÿÿ ÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿÿ ÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿ ÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿ</Text><Text id="56265" page="2">Requirements: Industrial Automation and Control Systems Network ÿÿÿÿ ÿ ÿ ÿ ÿ ÿ</Text><Text id="56266" page="2">1.1 Objective ............................................................................................................................................................... 4 1.2 Target group ......................................................................................................................................................... 4 1.3 Provision ............................................................................................................................................................... 4 2 Introduction ................................................................................................................................................................. 4 3 Network engineering and design ................................................................................................................................ 5</Text><Text id="56267" page="2">3.1 General ................................................................................................................................................................. 5 3.1.1 Criticality assessment .................................................................................................................................... 7 3.2 Level 3 Technical network .................................................................................................................................... 7 3.3 Level 2 Technical network .................................................................................................................................... 8 3.4 Level 3 SAS network ............................................................................................................................................ 8 3.5 Level 2 SAS network ............................................................................................................................................ 8 3.6 Level 1 SAS field network .................................................................................................................................... 9 3.6.1 General ......................................................................................................................................................... 9 3.6.2 Field Network traffic segregation ................................................................................................................... 9 3.6.3 PRP field networks ........................................................................................................................................ 9 3.6.3.1 Non-IEC 61850 PRP field network topology .......................................................................................... 10 3.6.3.2 IEC 61850 PRP network ....................................................................................................................... 10</Text><Text id="56268" page="2">4 Software ....................................................................................................................................................................... 11 4.1 General ................................................................................................................................................................. 11 4.2 Equipment message logging ................................................................................................................................ 12 4.3 Message log monitoring software ........................................................................................................................ 12 4.4 Management software .......................................................................................................................................... 12 4.5 Identity and access management software ......................................................................................................... 13</Text><Text id="56269" page="2">5 Components ................................................................................................................................................................. 13 5.1 General ................................................................................................................................................................. 13 5.2 Standardisation ..................................................................................................................................................... 14 5.3 Network equipment .............................................................................................................................................. 14 5.3.1 Firewalls ......................................................................................................................................................... 14 5.4 Computers ........................................................................................................................................................... 15 5.4.1 Servers ........................................................................................................................................................... 15 5.4.2 Clients ........................................................................................................................................................... 15 5.4.3 Virtual computers .......................................................................................................................................... 15 5.5 Provisioning of new devices / replacement of devices ........................................................................................ 16 6 Backup and recovery ................................................................................................................................................... 16 7 Testing .......................................................................................................................................................................... 16 7.1 Test during implementation .................................................................................................................................. 16 7.2 Test during commissioning .................................................................................................................................. 16 8 Additional information ................................................................................................................................................... 16</Text><Text id="56270" page="3">ÿ ÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿ ÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ</Text><Text id="56272" page="3">8.1 Definition and abbreviations ................................................................................................................................ 16 8.1.1 Definitions ..................................................................................................................................................... 16 8.1.2 Abbreviations ................................................................................................................................................ 22 8.2 Changes from previous version ............................................................................................................................ 23 8.3 References ........................................................................................................................................................... 23</Text><Text id="56274" page="4">Page 4 of 23 ÿ ÿ ÿÿÿ ÿ ÿ ÿÿÿÿÿÿÿ ÿÿÿÿ ÿÿ ÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿ ÿÿ ÿÿ ÿÿ ÿÿÿÿÿ ÿÿ ÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿ ÿÿÿÿÿÿ ÿÿÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿ ÿ ÿÿÿÿÿ ÿ ÿ ÿÿ ÿÿÿÿ ÿ ÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿÿÿ ÿÿ ÿ ÿÿ ÿÿÿÿÿ ÿ ÿ ÿÿÿÿÿÿÿ ÿÿÿ ÿÿ ÿÿ ÿÿ ÿÿ ÿÿ ÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿ ÿ ÿÿ ÿÿÿÿÿ ÿÿÿ ÿÿ ÿÿÿ ÿÿÿ ÿÿ ÿÿÿ ÿ ÿÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿ ÿ ÿÿÿÿÿ ÿÿÿÿ ÿ ÿÿ ÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿ ÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿ ÿ ÿÿ ÿ ÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿ ÿÿÿÿ ÿÿÿ ÿ ÿÿ</Text><Text id="56275" page="4">1.1 Objective The objective of this document is to define design requirements for the on-premise Industrial Automation and Control Systems (IACS) Ethernet-based networks, and technical requirements for network and client / server equipment used in IACS. Many of the requirements in this document will aid compliance with TR1658.</Text><Text id="56276" page="4">IACS covers in this context all networked systems installed on-premise to facilitate the production facility operations, e.g. Industrial Control Systems (ICS), condition monitoring systems, telecommunication infrastructure, operational management systems, etc.</Text><Text id="56277" page="4">For modifications to systems in operation some requirements in this document may conflict with the installed solution. Conflicts are to be assessed during the front-end engineering phase, and where local design will be maintained, substitution/addendum requirements should be made in accordance with TR0002 “Management system principles”.</Text><Text id="56278" page="4">The project must identify whether Company provided items should be utilized for parts of deliveries, e.g. monitoring and management software, software licenses, equipment hardware etc.</Text><Text id="56279" page="4">1.2 Target group The target group for this document is personnel that specify, engineer, fabricate, install, maintain, modify, upgrade or operate IACS networks.</Text><Text id="56280" page="4">1.3 Provision Provision is made in Company Management System (TR3030 “Automation, Technical requirements and standards”).</Text><Text id="56281" page="4">The IACS are critical for enabling a safe, efficient and sustainable operation of the production facility, and therefore have high demands regarding network availability and data integrity. Due to the IACS critical function they also are a high risk target for cyber threats.</Text><Text id="56282" page="4">It is therefore important that the network design and the components used in the network, enables secure resilient quality network services. Figure 1 below visualise a basic network architecture for an upstream oil &amp; gas production facility that incorporate security through zones and conduits, and availability through pre-defined network types. Note that additional conduits may apply based on design choices made.</Text><Text id="56283" page="4">Supervisory monitoring and network management is a prerequisite to enable an safe and efficient operation of the networks. This requires standardisation.</Text><Text id="56284" page="4">As such the main strategy is to require strong and resilient IACS network infrastructure, and require the use of firewalls, VLANs and QoS to protect the IACS components to the greatest practical degree from cyber threats and disturbances in</Text><Text id="56285" page="4">Such a strong network infrastructure generally requires managed and redundant networks, preferably with zero fail-over time in case of a network failure or network maintenance. Each IACS device or computer is connected directly to a switch to allow the network to control the traffic going to the device.</Text><Text id="56286" page="4">In order to ensure cyber security and the integrity of the IACS system, the IACS network infrastructure is structured</Text><Text id="56288" page="5">Safety and Automation System Level 3 SAS Net Compar jre</Text><Text id="56289" page="5">6. Additional ICS internal networks as required by system specific requirement</Text><Text id="56290" page="5">ÿ ÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿ ÿÿÿ ÿÿÿÿÿ ÿ ÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿ ÿÿ ÿÿÿÿ ÿ ÿÿÿÿ ÿÿÿ ÿ ÿ ÿ ÿ</Text><Text id="56291" page="5">ÿ ÿ ÿ ÿÿ ÿÿÿ ÿÿÿ ÿÿÿ ÿÿ ÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿ ÿÿ ÿÿÿÿÿ ÿÿÿÿ</Text><Text id="56292" page="5">Requirements: Industrial Automation and Control Systems Network Classification: Internal</Text><Text id="56293" page="5">Network I [ Information Management ] | Management</Text><Text id="56294" page="5">Information II Condition II Production 1 1 Operational 11 Telecom 11 Network II Field Device Management 11 Monitoring 11 Optimalisation II Support II systems II Management II Management</Text><Text id="56295" page="5">according to IEC 62264-1:2013-05 clause 5.2.1, also known as the Purdue Architecture for IACS&quot;. The different levels can be seen in figure 1 below. Note the locations of the firewalls, and that it is generally permitted for control and service traffic to share the same physical network where necessary.</Text><Text id="56296" page="5">The document also states some common requirements to computers used for engineering and monitoring purposes. This to ensure we utilize shared resources where applicable, increased standardization and simplify operation/maintenance of the equipment.</Text><Text id="56297" page="5">Please note that additional requirements may apply as specified in other discipline technical requirement documents.</Text><Text id="56298" page="5">3.1 General SR-77004 - The following physical IACS network infrastructures shall be available at the facility:</Text><Text id="56299" page="5">4. Level 2 SAS HMI and Control networks</Text><Text id="56300" page="5">5. Level 1 SAS Field networks as applicable</Text><Text id="56301" page="5">Security Level Targets ( SL-T4 1 [ SL-T3 ] ( SL-T2 ] ( SL-T1</Text><Text id="56302" page="5">ÿÿ ÿ ÿÿÿÿ ÿ ÿÿÿ ÿÿÿÿÿÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿ</Text><Text id="56303" page="5">ÿÿ ÿ ÿÿÿÿ ÿ ÿÿ ÿÿ ÿÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿ</Text><Text id="56304" page="5">Figure 1 Example of Upstream Oil &amp; Gas facility zones and conduits model. SL-T levels in the figure are only guidance. TR1658 shall be followed to assess which SL-T to be used and placement of conduits.</Text><Text id="56305" page="5">Not all network connections in the figure between &quot;control zones&quot; are necessarily used for control traffic, some information and general alarms may be transported through the same physical layer, e.g. for CC3 connections to the Field network, as such information normally is received through the control nodes by the SAS system.</Text><Text id="56306" page="6">1. System independency, reliability, availability, maintainability, and performance</Text><Text id="56307" page="6">ÿÿÿÿÿ ÿÿÿ ÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿ ÿÿ ÿÿ ÿÿÿÿ ÿÿÿÿÿ ÿ ÿÿ ÿÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿ ÿÿ ÿÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿ ÿ ÿÿÿÿ ÿ ÿÿ ÿ ÿÿ ÿ ÿÿÿ ÿÿ ÿ ÿÿÿÿÿÿ ÿÿ ÿÿ ÿÿÿ ÿÿÿÿ ÿÿÿ ÿÿÿ ÿ ÿÿÿ ÿÿ ÿÿ ÿÿÿÿÿ ÿÿÿÿÿ ÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿ ÿÿÿ ÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿ ÿÿ ÿ ÿÿ ÿÿ ÿÿÿÿÿ ÿÿÿ ÿÿ ÿÿ ÿÿÿ ÿÿ ÿ ÿÿ ÿÿ ÿÿ ÿÿ ÿÿ ÿÿ ÿÿÿ ÿÿÿÿÿ ÿÿÿÿ ÿÿ ÿÿÿÿ ÿÿ ÿ ÿÿ ÿÿÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿ ÿÿ ÿ ÿÿ ÿÿ ÿÿÿÿÿ ÿÿÿ ÿ ÿÿ ÿÿ ÿÿÿ ÿÿÿ</Text><Text id="56308" page="6">If connectivity is needed between HIPPS/FWP/EmG to ensure monitoring and possible remote this may be solved by a control mechanism in a conduit.</Text><Text id="56309" page="6">SR-77134 - The IACS networks shall support integrated security concepts as defined by TR1658.</Text><Text id="56310" page="6">SR-86592 - The IACS network design shall safeguard aspects for facility operation, system independence, system performance and technology used.</Text><Text id="56311" page="6">SR-86591 - Effort shall be made to share infrastructure within the individual physical infrastructures where possible based on risk assessments done. Requirements to the following needs to be maintained in the design:</Text><Text id="56312" page="6">SR-76647 - Separate network management solutions customized to Company operational model shall be designed for:</Text><Text id="56313" page="6">1. Level 3 Technical network and firewall equipment, including connected EPU control system edge network switches</Text><Text id="56314" page="6">2. Level 2 Technical network and firewall equipment, including connected EPU control system edge network switches</Text><Text id="56315" page="6">3. Level 3, 2 and 1 SAS network and firewall equipment</Text><Text id="56316" page="6">The system specific TRs may put additional requirements to management solution for additional IACS internal networks.</Text><Text id="56317" page="6">SR-86589 - The high availability networks design shall be limited to use the following network protocols in accordance with IEC 62439:</Text><Text id="56318" page="6">• Parallel Redundancy Protocol (PRP) when zero fail over time is required</Text><Text id="56319" page="6">• High-availability Seamless Redundancy (HSR) when zero fail over time is required</Text><Text id="56320" page="6">SR-86756 - RSTP shall not be used as a network redundancy protocol in high availability networks, but may be used to add redundancy to equipment connection on edge switch ports.</Text><Text id="56321" page="6">SR-92089 - Network edge switch ports (where Devices or Computers are connected) shall have BPDU guard enabled.</Text><Text id="56322" page="6">SR-86588 - The networks shall have a high availability design when the data communicated is critical for safety or production, or if the connected networked component requires a high availability data link.</Text><Text id="56323" page="6">SR-86587 - The networks shall have capacity to handle the data load for all operational modes. SR-77150 - The IACS networks shall be scalable with respect to capability and capacity. SR-77160 - The IACS networks shall be based on recognised open industry standards. SR-77459 - The IACS networks shall support Quality of Service (QoS) functionality. SR-86585 - The networks shall support Virtual Local Area Network (VLAN) functionality.</Text><Text id="56324" page="6">SR-77669 - The IACS networks shall prioritise IACS dependent data traffic over non-dependent data traffic if deployed on a shared physical network infrastructure.</Text><Text id="56325" page="6">SR-86586 - The IACS networks design shall protect the networked components from unwanted network traffic where</Text><Text id="56326" page="6">relevant. SR-77163 - The IACS networks shall be able to distribute time to networked components. SR-77648 - Time in redundant network configurations shall be sourced from redundant Real Time Clocks. SR-77133 - The IACS networks shall support end-to-end connectivity for management data where required.</Text><Text id="56328" page="7">Page 7 of 23 ÿÿ ÿÿ ÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿÿÿ ÿÿ ÿ ÿ ÿÿÿÿÿ ÿ ÿÿ ÿÿ ÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿ ÿÿ ÿÿ ÿ ÿÿÿÿÿ ÿÿ ÿÿ ÿÿ ÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿ ÿÿ ÿÿÿÿÿÿ ÿ ÿÿ ÿ ÿÿÿÿÿÿÿ ÿ ÿ ÿÿÿ ÿÿÿÿÿÿ ÿÿÿ ÿÿ ÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿ ÿ ÿÿÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿ ÿ ÿÿ ÿÿÿÿÿÿ ÿ ÿÿ ÿÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿÿÿÿ ÿÿ ÿÿÿÿ ÿ ÿÿÿÿÿÿÿ ÿÿ ÿÿ 2 ÿÿ ÿÿÿ ÿÿÿ ÿÿ ÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿÿ ÿÿ ÿÿ ÿ</Text><Text id="56329" page="7">SR-79218 - The network IP plan shall be pre-approved by Company.</Text><Text id="56330" page="7">SR-78009 - Computers, except server hardware used for virtual hosts, shall not be connected to different networks by- passing installed firewalls.</Text><Text id="56331" page="7">SR-91917 - Server hardware used for virtual hosts shall not be connected across different Purdue levels.</Text><Text id="56332" page="7">SR-86593 - If encrypted data links are used between networks on different levels, the traffic shall be decrypted before entering end-point firewalls with DPI and IDS enabled.</Text><Text id="56333" page="7">SR-86697 - The IACS systems shall be designed so that the use of (Supplier) laptops and similar portable computers is not required for configuration, operation or maintenance.</Text><Text id="56334" page="7">SR-86696 - Software applications necessary for maintenance, configuration and parameterisation of the IACS systems shall be included and installed on Engineering work stations.</Text><Text id="56335" page="7">SR-76646 - Data links shall be identified and classified in accordance with its consequence for facility safety, information security and production.</Text><Text id="56336" page="7">The framework described in NOG 123 can be used for this assessment.</Text><Text id="56337" page="7">SR-77911 - Cyber Security Risk assessment for the System under Consideration (SuC, ref TR1658) shall be done to identify the network infrastructure to be utilized.</Text><Text id="56338" page="7">3.2 Level 3 Technical network The Level 3 Technical network should be used for systems with facility functions and to provide network connection to off- premise Company IT solutions through the Company secure access solution.</Text><Text id="56339" page="7">SR-86613 - Systems critical for facility safety or production shall not be dependent of the Level 3 Technical network to execute its function.</Text><Text id="56340" page="7">SR-86612 - The Level 3 Technical core network layer shall have a fault tolerant design.</Text><Text id="56341" page="7">A Level 3 Technical distribution network layer should be used where there is a need for aggregating network layers and provide unique connectivity services within a distribution network segment.</Text><Text id="56342" page="7">SR-86617 - The Level 3 Technical network shall provide distribution, policy control, and isolation points between the network segment and the rest of the IACS networks.</Text><Text id="56343" page="7">SR-86616 - The Level 3 Technical network shall have a fault tolerant design towards the core or distribution network.</Text><Text id="56344" page="7">SR-86615 - The Level 3 Technical network shall be connected to a high availability firewall solution in the Company secure access solution for secure data traffic within and to/from the network.</Text><Text id="56345" page="7">SR-77773 - The Level 3 Technical network components shall be compatible and integrated with Company centralised</Text><Text id="56347" page="8">SR-86626 - The Level 2 SAS control edge switches shall have a high availability design towards the core network.</Text><Text id="56348" page="8">ÿÿÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿ ÿ ÿÿ ÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿ ÿ ÿÿÿÿ ÿÿÿ ÿ ÿÿÿÿÿ ÿÿÿÿÿÿ ÿ ÿÿÿÿ &quot;ÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿ ÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿ ÿÿ ÿÿÿÿÿÿ ÿ ÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿ ÿÿ ÿÿ ÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿ ÿÿ ÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿ ÿ ÿÿÿÿ ÿÿ ÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿ ÿÿÿÿÿ ÿÿ ÿ ÿÿÿ ÿ ÿ</Text><Text id="56349" page="8">3.3 Level 2 Technical network The Level 2 Technical network should be used for operational management solutions in IACS other than SAS that is considered high critical based on the Cyber Security risk assessment, and to provide network connection to solutions in the Level 3 IACS network.</Text><Text id="56350" page="8">SR-86620 - Systems critical for facility safety or production shall not be dependent of the Level 2 Technical network to execute its function.</Text><Text id="56351" page="8">SR-86619 - The Level 2 Technical core network layer shall have a fault tolerant design.</Text><Text id="56352" page="8">A Level 2 Technical distribution network layer should be used where there is a need for aggregating network layers and provide unique connectivity services within a distribution network segment.</Text><Text id="56353" page="8">SR-86623 - The Level 2 Technical network shall have a fault tolerant design towards the core or distribution network.</Text><Text id="56354" page="8">SR-86622 - The Level 2 Technical network shall have a high availability firewall solution installed to restrict data traffic within and to/from the network.</Text><Text id="56355" page="8">3.4 Level 3 SAS network The Level 3 SAS network should be used for operational management solutions in SAS and to provide network connection to solutions in the Level 3 Technical network.</Text><Text id="56356" page="8">SR-86636 - Systems critical for facility safety or production shall not be dependent of the Level 3 SAS network to execute its function.</Text><Text id="56357" page="8">SR-86635 - The Level 3 SAS core network layer shall have a fault tolerant design.</Text><Text id="56358" page="8">SR-86634 - The Level 3 SAS network shall provide distribution, policy control, and isolation points between the network segment and the rest of the network.</Text><Text id="56359" page="8">SR-86633 - The Level 3 SAS network shall have a fault tolerant design towards the core network.</Text><Text id="56360" page="8">SR-86632 - The Level 3 SAS network shall have a high availability firewall solution installed for secure data traffic within and to/from the network.</Text><Text id="56361" page="8">3.5 Level 2 SAS network The Level 2 SAS HMI network should be used for the HMI system in SAS and to provide connection to solutions in the Level 3 and 1 SAS networks.</Text><Text id="56362" page="8">SR-86631 - The Level 2 SAS HMI core network layer shall have a high availability design. SR-86627 - The Level 2 SAS HMI edge switches shall have a high availability design towards the core network.</Text><Text id="56363" page="8">The Level 2 SAS control networks should be used for controller to controller data traffic and to provide network connection to solutions in the Level 2 SAS network and Level 1 SAS field networks.</Text><Text id="56364" page="8">SR-86625 - The Level 2 SAS control core network layer shall have a high availability design.</Text><Text id="56365" page="9">SR-86639 - The Level 1 SAS field networks layer shall have a high availability design.</Text><Text id="56366" page="9">SR-77672 - PRP field networks shall have a dual star design as indicated in the figure below.</Text><Text id="56367" page="9">Page 9 of 23 ÿ ÿ ÿÿÿ ÿ ÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿ ÿ ÿÿ ÿ ÿÿ ÿÿ ÿ ÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿ ÿÿÿÿÿ ÿ ÿÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿ ÿ ÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿ ÿÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿÿ ÿÿ ÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿ ÿÿ ÿÿÿÿÿÿÿÿ ÿÿÿÿ</Text><Text id="56368" page="9">3.6.1 General The Level 1 SAS field networks should be used for data traffic to/from field devices and to provide network connection to solutions in the Level 2 SAS control networks.</Text><Text id="56369" page="9">SR-86644 - A SAS Level 1 field distribution network layer shall be used where there is a need for aggregating network layers and provide unique connectivity services within a distribution network segment.</Text><Text id="56370" page="9">SR-86643 - Where independent A and B cable routing is required, separate Level 1 SAS core network switches shall be used.</Text><Text id="56371" page="9">SR-86642 - The Level 1 SAS PCS field networks shall have a redundant firewall solution installed for enabling secure data links between the field devices and the management solutions.</Text><Text id="56372" page="9">SR-86687 -The level 1 IEC 61850 network shall use PRP, specified in Clause 4 of IEC 62439-3:2012, both for Station Bus and (if implemented) Process Bus.</Text><Text id="56373" page="9">3.6.2 Field Network traffic segregation SR-86683 - Each SAS logic solver shall have a separate VLAN for field network communication.</Text><Text id="56374" page="9">Such VLAN may be shared for PROFINET and Modbus TPC if a common port is used. VLAN may be shared between controllers required to communicate with the same devices.</Text><Text id="56375" page="9">SR-78573 - Non-SAS logic solvers in Class 2 packages, which use the field network to communicate to e.g. MCCs, shall have separate VLANs for this purpose.</Text><Text id="56376" page="9">SR-78572 - Level 2 Technical network traffic shall be in separate VLANs to the SAS VLANs, where the device supports this.</Text><Text id="56377" page="9">ÿÿÿÿÿÿÿÿÿ ÿÿÿ ÿÿ ÿ ÿÿÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿ ÿ ÿÿÿ</Text><Text id="56380" page="9">Figure 2 Diagram showing principle of locating the two PRP hubs physically separate</Text><Text id="56381" page="9">SR-78496 - Devices and computers which does not support PRP shall be connected using a redbox. SR-78494 - Devices and computers shall be connected to a port on a switch.</Text><Text id="56382" page="9">SR-78553 - If the SAS logic solver does not support PRP, one redbox shall be used for connecting PRP A and PRP B to the SAS A network, and another redbox shall be used for similar connection to the SAS B network.</Text><Text id="56383" page="9">SR-78551 - Communication to Level 2 Technical network shall be done through a separate redbox.</Text><Text id="56384" page="10">ÿÿÿ ÿÿ ÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿ ÿ ÿ ÿÿÿ ÿ ÿ</Text><Text id="56385" page="10">Motor Starter Cubicle Motor Starter Cubicle One or more VSDs</Text><Text id="56387" page="10">Figure 3 Principle drawing for non-IEC 61850 field network based on PRP, typically used for PROFINET and Modbus TCP.</Text><Text id="56388" page="10">MCC MCC MCC MCC MCC MCC MCC MCC MCC VSD VSD VSD</Text><Text id="56390" page="10">3.6.3.1 Non-IEC 61850 PRP field network topology In order to implement shared network infrastructure for the field ne works (IEC 61850 and non-IEC 61850) the non-IEC</Text><Text id="56391" page="10">Control system Control system Level 3 Technical network</Text><Text id="56392" page="10">Multicore Fiber Copper or Fiber PRP A net</Text><Text id="56394" page="10">PRP A PRP B Network SAS B net</Text><Text id="56396" page="10">ÿ ÿÿÿ ÿÿ ÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿÿÿ ÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿ ÿÿ ÿ ÿÿÿÿÿ ÿÿ ÿÿÿ ÿÿÿÿÿ</Text><Text id="56397" page="10">Individual Class 2 packages with dedicated SAS logic solvers may have individual links to e.g. a VSD, but communicate via the PCS field network to equipment from other packages (e.g. MCCs in electro packages).</Text><Text id="56398" page="11">Control system Control system Note: both PRP A and B (orange and green) and redundant A and B (red and blue) are available to suit the control system.</Text><Text id="56400" page="11">PRP A net PRP B net SAS A net SAS B net Service net</Text><Text id="56401" page="11">SR-78030 - Software licenses shall be registered to Company and activated before project handover to operation.</Text><Text id="56402" page="11">ÿÿÿ ÿÿ ÿÿÿÿ ÿÿ ÿÿÿÿÿÿÿÿ ÿÿÿ ÿ ÿÿ ÿÿÿ ÿÿÿÿÿ ÿ ÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿ ÿ ÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿ ÿÿÿ ÿÿ ÿÿÿÿ ÿÿ ÿ ÿÿÿ ÿÿÿ ÿÿ ÿ ÿ ÿ ÿÿÿÿÿ ÿ ÿÿÿÿ ÿÿ ÿÿÿ ÿÿ ÿÿ ÿ ÿ ÿÿÿ ÿÿ ÿÿ ÿÿÿ ÿÿ</Text><Text id="56403" page="11">HV Switchboard A HV Switchboard B MV Switchboards A MV Switchboards B LV Switchboard A LV Switchboard B</Text><Text id="56404" page="11">Figure 4 Principle drawing for IEC61850 station bus network topology using PRP</Text><Text id="56405" page="11">lEDs should connect to the network using PRP, without the use of a redbox. SR-78543 - Switches used in IEC 61850 networks shall not enable write MMS support. SR-78542 - Where PTP is required, switches used in IEC 61850 networks shall support PTP.</Text><Text id="56406" page="11">4.1 General SR-83694 - The project shall in due time get a final acceptance from Company on the software products chosen.</Text><Text id="56407" page="11">SR-83693 - The agreed official software version for all software components shall be available for installation before project handover to operation.</Text><Text id="56408" page="11">SR-83695 - All agreed official software patches shall be installed before project handover to operation. SR-83692 - The operating system shall be of Long-term Support (LTS) version where available.</Text><Text id="56409" page="12">ÿÿ ÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿ ÿ ÿ ÿ ÿÿÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿ ÿ ÿ ÿ ÿ ÿ ÿÿÿÿ ÿÿÿ ÿÿ ÿ ÿÿ ÿÿÿ ÿÿ ÿÿ ÿÿÿ ÿ ÿÿÿ ÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿ ÿÿ ÿÿÿ ÿÿÿÿÿ ÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿ ÿÿ ÿÿ ÿ ÿÿ ÿÿÿ ÿÿ ÿÿ ÿÿ ÿÿ ÿ ÿÿ ÿÿÿ. ÿÿÿ ÿÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿ ÿ ÿÿ ÿÿÿÿÿ ÿÿÿÿ ÿÿ ÿÿÿ ÿÿÿ ÿ ÿÿ ÿÿ ÿÿ ÿÿ ÿÿÿÿ ÿ ÿÿ ÿ ÿÿÿ ÿÿÿÿÿ ÿ ÿ ÿ ÿÿ ÿ ÿÿ ÿÿ ÿÿ ÿ ÿ ÿÿÿ ÿÿÿÿÿ ÿÿ ÿÿ ÿ ÿÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿÿ ÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿ ÿÿÿ ÿÿ ÿ ÿÿÿÿ ÿ ÿÿ ÿ</Text><Text id="56410" page="12">4.2 Equipment message logging SR-78483 - The network equipment and networked devices message logs shall be based on recognised open standards. The message logs shall also cover security related alarms and events, including remote desktop protocol usage.</Text><Text id="56411" page="12">For network equipment Syslog (RFC 5424) or SNMP traps are examples of such standards</Text><Text id="56412" page="12">For clients and servers running Microsoft Windows operating system, the Default Audit logging must enable Success/Failure on account logon events, account management, logon events, object access, policy change, system events.</Text><Text id="56413" page="12">6. Cyber security related alarms and events, including remote desktop protocol usage</Text><Text id="56414" page="12">SR-78482 - The network and networked equipment shall provide data for inventory, backup status, health and performance.</Text><Text id="56415" page="12">Use of staging should be considered to avoid unnecessary exposure to external networks.</Text><Text id="56416" page="12">SR-81821 - The message log monitoring software and protocols shall be based on recognised open standards.</Text><Text id="56417" page="12">SR-78484 - The facility shall have a message log monitoring solution for capture and storage of message logs from all networked IACS.</Text><Text id="56418" page="12">SR-78477 - The message log monitoring solution shall provide a secure interface for communicating message log data to other Company systems.</Text><Text id="56419" page="12">SR-78478 - The message log monitoring solution shall be able to save all messages to files on a Company file share.</Text><Text id="56420" page="12">SR-78464 - The message log monitoring solution shall include a historian module for capturing and storing time stamped equipment data.</Text><Text id="56421" page="12">SR-78470 - The message log monitoring solution shall as a minimum provide the following information:</Text><Text id="56423" page="12">4.4 Management software The management software covers configuration management of network equipment and client/server equipment. The management software should be based on recognised open standards. SR-86597 - The management software communication with equipment in scope shall utilise secure protocols. SR-81833 - The management software shall support the life-cycle of services needed to install, configure, troubleshoot,</Text><Text id="56425" page="12">repair and maintain equipment throughout the life of the facility.</Text><Text id="56426" page="12">SR-81838 - The management software shall include a module for capturing changes to the hardware configuration, back- up the configurations and ability to load them to the hardware component.</Text><Text id="56427" page="12">SR-81837 - It shall be possible to recover configuration data on the management software from backups.</Text><Text id="56428" page="13">ÿÿÿÿ ÿÿ ÿÿÿÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿ ÿÿ ÿ ÿÿÿÿÿ ÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿ ÿ ÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿ ÿÿÿ ÿ ÿÿÿÿÿ ÿÿÿ ÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿ ÿÿ ÿÿ ÿ ÿ ÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿ ÿÿÿ ÿÿ ÿÿ ÿÿ ÿ ÿ ÿÿ ÿÿ ÿ ÿ ÿ ÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿÿÿ ÿÿÿ ÿ ÿ ÿÿÿ ÿÿ ÿÿÿ ÿÿÿÿ ÿÿÿ ÿÿ ÿ ÿÿ ÿ ÿÿ ÿÿ ÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿ ÿ ÿÿÿÿÿÿ ÿÿÿ ÿÿÿ ÿÿ ÿÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿ ÿÿÿ ÿ ÿÿ ÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿ ÿ ÿÿÿ ÿÿÿÿÿ ÿÿÿ ÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿ ÿÿÿÿ ÿÿ ÿ ÿÿÿÿÿ ÿ ÿÿ ÿÿÿÿÿ ÿÿ ÿÿÿÿÿÿ</Text><Text id="56429" page="13">Requirements: Industrial Automation and Control Systems Network Classification: Internal</Text><Text id="56430" page="13">4.5 Identity and access management software The Identity and access management software covers user access management and security management of network equipment and client/server equipment.</Text><Text id="56431" page="13">SR-86601 - The system shall support different levels of user access rights to prevent unauthorised access to system and application software.</Text><Text id="56432" page="13">SR-86600 - The system shall have a role-based access allowing assignment of users/user groups to roles.</Text><Text id="56433" page="13">SR-86599 - It shall be possible to configure the access roles to limited parts of the system and/or limited parts of the application software.</Text><Text id="56434" page="13">SR-86598 - The identity and access management software shall include functionality for cyber security controls including audit controls. As a minimum the following are to be included:</Text><Text id="56435" page="13">1. Identity management: Manage identities for accessing the network management, manage external account service connection. 2. Access management: Manage accesses, roles, privileges for roles, mapping to identities 3. Accounts: Manage accounts that access the system management server resources</Text><Text id="56436" page="13">4. Credentials Management; Manage identity proof levels, interactions with Identity/account service</Text><Text id="56438" page="13">SR-86605 - The project shall in due time get a final acceptance from Company on the network equipment and computer hardware standardisation chosen.</Text><Text id="56439" page="13">SR-79188 - Replacement of redundant hardware components shall be possible during normal operation, without any loss of functionality or production.</Text><Text id="56440" page="13">SR-86604 - The network equipment and networked computers shall be able to export message logs including alarm and events (security events included).</Text><Text id="56441" page="13">SR-86603 - The networked components shall support connectivity without need of extensive manual integration services. SR-86608 - The networked components shall communicate by the use of Ethernet. SR-86607 - All unused communication ports on network equipment and networked components shall be locked, disabled or protected by software means. If not possible through software, a physical port lock product shall be used.</Text><Text id="56442" page="13">SR-86606 - The network equipment and networked components shall handle wire-speed network storms gracefully, i.e. network port may be shut down temporarily but shall automatically be re-enabled when the storm has ended.</Text><Text id="56444" page="13">SR-86699 - Devices with a Ethernet service port; these shall be connected to the network. SR-78500 - Devices with a serial/USB service port; these shall be connected to the network using a serial/IP server.</Text><Text id="56445" page="13">It is not necessary to connect multiple service ports if the functionality is already taken care of for the device.</Text><Text id="56446" page="13">SR-78501 - Devices with only one network interface shall support both control and service traffic.</Text><Text id="56447" page="14">solution, including a HMI panel from the user&apos;s work desk, for open/close of predefined firewall rulesets.</Text><Text id="56448" page="14">Page 14 of 23 ÿ ÿ ÿÿÿ ÿ ÿ ÿÿ ÿÿ ÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿ ÿ ÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿ ÿ ÿ ÿÿÿ ÿÿ ÿ ÿÿ ÿÿ ÿÿÿ ÿÿÿÿÿÿÿ ÿÿÿ ÿÿ ÿÿÿÿ ÿÿÿÿ ÿ ÿÿ ÿÿÿÿ ÿÿ ÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿ ÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿ ÿÿÿ ÿ ÿÿÿÿ ÿÿÿÿ ÿÿ ÿ</Text><Text id="56449" page="14">ÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿ ÿÿ ÿ ÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿ ÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿ ÿ ÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿ ÿ</Text><Text id="56450" page="14">5.2 Standardisation The network equipment for use in protected area should be from one manufacturer and of the same product family. The network equipment for use outside protected area should be from one manufacturer and of the same product family. SR-79191 - The client hardware shall be from one manufacturer and of the same product family within a system. SR-79186 - The server hardware shall be from one manufacturer and of the same product family within a system.</Text><Text id="56451" page="14">SR-86610 - The network equipment and computer hardware shall be commercial of the shelf products that are suitable for its intended use.</Text><Text id="56452" page="14">5.3 Network equipment SR-86611 - The network equipment shall support the communication protocol used. SR-79202 - The network equipment shall have rack or DIN rail mount. SR-79200 - The network equipment shall have minimum 2 up-link ports. SR-79199 - The internal power supplies in the network equipment shall be active redundant. SR-79208 - The network equipment for use outside protected area shall be fan-less.</Text><Text id="56453" page="14">SR-79207 - The network equipment used in the core or distribution networks shall have minimum 1 Gigabit/s bandwidth on uplinks and edge ports.</Text><Text id="56454" page="14">SR-79210 - The network equipment shall be able to be managed from the management software.</Text><Text id="56455" page="14">SR-79212 - The network equipment shall do automatic startup with correct configuration without any user intervention after loss of power.</Text><Text id="56456" page="14">SR-79209 - The network equipment’s configuration shall be available for online or offline upload after replacement of component.</Text><Text id="56457" page="14">SR-81377 - Where redbox functionality is needed; the edge switch shall support redbox functionality.</Text><Text id="56458" page="14">5.3.1 Firewalls SR-78016 - Firewalls shall deny data flow by default. SR-78015 - All data flows shall explicitly be configured in the firewall rulesets.</Text><Text id="56459" page="14">SR-78021 - The main firewall solutions at Level 3 Technical network, Level 3 SAS Technical network and Level 2 Technical network shall be redundant firewall cluster solutions with state synchronisation that support Deep Package Inspection (DPI) and Intrusion Detection System (IDS).</Text><Text id="56460" page="14">SR-84565 - The management interface of the firewalls shall be protected. SR-86649 - The main firewall at Level 2 Technical network shall be integrated with an independent managed barrier</Text><Text id="56461" page="15">SR-92429 - Virtual hardware allocation shall be in accordance to actual needs and have the capacity to handle predicted</Text><Text id="56462" page="15">Page 15 of 23 ÿ ÿ ÿÿÿ ÿ ÿ ÿ ÿÿÿÿ ÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿ ÿÿ ÿ ÿÿ ÿÿÿÿÿÿ ÿÿÿ ÿÿ ÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿ ÿ ÿÿ ÿ ÿÿÿ ÿÿÿÿÿÿ ÿÿÿ ÿ ÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿ ÿÿÿÿ ÿÿÿÿÿ ÿ ÿÿÿÿÿÿÿÿÿ ÿÿÿÿ ÿ ÿÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿ ÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿÿ ÿÿ ÿÿÿÿÿ ÿÿ ÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿ ÿÿ ÿÿÿÿ ÿÿ ÿÿÿÿÿÿ ÿ ÿ ÿÿÿ ÿ ÿ ÿÿÿÿ ÿÿÿÿÿÿÿ ÿÿÿ</Text><Text id="56463" page="15">SR-77781 - Server hardware with server operating system shall be used as run-time environment when Level 2 or Level 3 application software demands for 24x7 operation.</Text><Text id="56464" page="15">SR-77780 - Server hardware shall run a virtualisation environment. SR-78010 - Server hardware shall include a dedicated out-of-band management interface. SR-79217 - The server hardware shall have rack or DIN rail mount.</Text><Text id="56465" page="15">SR-79216 - The server hardware shall be fault tolerant against disk failures and with automatic online recovery when replacing a disk.</Text><Text id="56466" page="15">SR-92430 - If a Hypervisor cluster is installed for redundancy, redundancy on management shall be implemented according to best practice from the applicable Hypervisor vendor.</Text><Text id="56467" page="15">SR-79215 - The internal power supplies and fans in the server hardware shall be active redundant. SR-78032 - All application software with a demand for 24x7 operation installed in the server shall run as a service in the background, independently whether interface user is logged in or out to the applications.</Text><Text id="56468" page="15">5.4.2 Clients SR-77779 - Client hardware with end user operating system shall be used when functionality is to provide HMI to users working in protected area.</Text><Text id="56469" page="15">Some HMIs may be delivered as built-in panels, included as part of PLCs etc, thereby not using standard client hardware.</Text><Text id="56470" page="15">SR-77782 - Clients shall run as bare metal installation, no virtualisation required.</Text><Text id="56471" page="15">The client hardware may be removed if the system solves the same with a virtual computer as part of a Server hardware.</Text><Text id="56472" page="15">5.4.3 Virtual computers SR-86609 - Virtual machines shall run on a server hardware.</Text><Text id="56473" page="15">SR-78012 - A dedicated physical network port shall be used in the server hardware for connecting the Hypervisor management interface to the relevant management system.</Text><Text id="56474" page="15">SR-78008 - Virtual machines shall be supplied in Open Virtualization Format (OVF) if the virtual machine is to be implemented on a Hypervisor from another delivery.</Text><Text id="56475" page="15">SR-78007 - All virtual disks shall be thick provisioned Lazy zeroed. Thick provisioned Eager zeroed virtual disks may be used if vendor application requires it.</Text><Text id="56476" page="16">SR-78023 - The provisioning of the new device shall be done using applications on the EWS.</Text><Text id="56477" page="16">procedure for update and scanning shall be made and executed.</Text><Text id="56478" page="16">ÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿ ÿÿ ÿÿÿ ÿ ÿÿ ÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿÿ ÿÿÿÿ ÿÿ ÿÿ ÿÿÿ ÿÿÿ ÿÿÿ ÿ ÿÿÿÿ ÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿ ÿÿÿ ÿÿÿ ÿÿÿÿ ÿÿ ÿ ÿÿÿÿÿÿ ÿ ÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿ ÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿ ÿ ÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿ ÿ</Text><Text id="56479" page="16">5.5 Provisioning of new devices / replacement of devices SR-78024 - Supplier shall provide a procedure, and necessary hardware and software (e.g. cables, converters, drivers), used for initial provisioning of replacement parts (i.e. a new out-of-the-box device).</Text><Text id="56480" page="16">SR-78027 - The provisioning procedure shall include enabling of ports, configuring IP addresses and other details necessary for the new device to be inserted into the network and receive its main configuration from the EWS.</Text><Text id="56481" page="16">SR-78026 - Initial configuration using a network cable shall be preferred over USB.</Text><Text id="56482" page="16">6 Backup and recovery SR-78034 - The facility shall provide for shared backup solution for the network connected systems.</Text><Text id="56483" page="16">SR-78033 - Larger infrastructures (e.g. SAS) shall provide their own internal backup solution which may utilize the shared facility solution for offline backup.</Text><Text id="56484" page="16">SR-78036 - To reduce the amount of data being synchronized to onshore centralized storage for offsite backup, systems shall use block level backup rotation when offline backup is copied to the shared facility solution.</Text><Text id="56485" page="16">SR-79219 - The components configuration shall be available for online or offline upload after replacement of equipment.</Text><Text id="56486" page="16">7.1 Test during implementation SR-78784 - During the implementation of a system it shall be planned for a Cyber Security and Network test. SR-78788 - It is required that supplier tests specifications are extended to include test procedure and expected results.</Text><Text id="56487" page="16">7.2 Test during commissioning SR-78787 - When the system is delivered and to be powered up for commissioning activities it shall be planned for necessary activities to ensure remaining interface and communication connections are done.</Text><Text id="56488" page="16">SR-78786 - To ensure the integrity of the delivered system before connecting it to the network a Cyber Security</Text><Text id="56491" page="16">Application In this document, this word refers to software applications which are installed on a general-purpose Operating System.</Text><Text id="56493" page="16">Application software Production facility specific run-time applications I configuration</Text><Text id="56494" page="16">Availability Property of ensuring timely and reliable access to and use of control system information and functionality. (Source: IEC</Text><Text id="56495" page="17">Page 17 of 23 ÿÿ ÿÿ ÿ ÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿ</Text><Text id="56496" page="17">ÿÿÿ ÿ ÿÿ ÿ ÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿ ÿ ÿÿÿÿ ÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿÿ ÿÿ ÿ ÿ ÿÿ ÿ ÿÿÿ ÿÿÿÿ ÿ ÿ ÿ ÿÿÿ ÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿ ÿÿÿÿÿÿÿ ÿÿ ÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿ ÿ ÿ ÿÿ ÿÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿÿÿÿ ÿÿ ÿÿÿÿÿ ÿÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿÿÿÿ ÿÿÿÿ ÿ ÿÿÿÿÿ ÿÿÿÿÿ ÿÿ ÿÿÿÿÿÿÿÿ ÿÿ ÿÿ ÿ ÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿÿÿ ÿÿÿÿ ÿ ÿÿÿÿÿÿ ÿÿÿ ÿÿ ÿÿÿ ÿÿÿ ÿÿ ÿÿ ÿ ÿÿÿÿÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿÿÿÿ ÿ ÿÿ ÿÿÿÿÿÿ ÿÿÿÿ ÿ ÿÿÿÿ ÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿ ÿÿ ÿÿÿ ÿÿ ÿÿÿÿ</Text><Text id="56497" page="17">Block level backup In block-level incremental backups, the backup software identifies the data blocks that have been changed since the most recent backup job and copies them to the backup repository. Block-level tracking allows a more granular approach compared to backing up entire files, as in file-level incremental backup.</Text><Text id="56498" page="17">BPDU guard PortFast BPDU guard prevents loops by moving a non-trunking port into an &quot;errdisable state&quot; when a BPDU is received on that port. When you enable BPDU guard on the switch, spanning tree shuts down PortFast-configured interfaces that receive BPDUs instead of putting them into the spanning tree blocking state.</Text><Text id="56499" page="17">Can Statements of possibility and capability, whether material, physical or causal. (Source: Company Management system)</Text><Text id="56500" page="17">Client When preceding the word “Computer”, a “Client Computer” means a computer which is typically used to access other Components, for operation or maintenance tasks such as troubleshooting, diagnostics or configuration. A Client Computer does not need to run 24/7, and applications can depend on a user session (i.e. a human user logged in) to be started.</Text><Text id="56501" page="17">The word “Client” may also be used about one of the two roles (“Client” or “Server”) in a network protocol connection, such as “SSH Client”. In this meaning, the protocol name is always preceding the word “Client”.</Text><Text id="56502" page="17">The term “Client Application” may also be used. This means that the application has a Client I Server architecture, and the “Client Application” refers to one of the two peers of this application architecture.</Text><Text id="56503" page="17">Components A common term for Computers, Devices and Network Equipment.</Text><Text id="56504" page="17">Computer A Commercial-Off-The-Shelf (COTS) computer running a general-purpose operating system like Windows Server, Windows LTSC or Linux based operating systems such as (but not limited to) Ubuntu Server, RedHat Server etc. The word “Computer” reflects an instance of an operating system, and this can be installed either on a dedicated, physical computer, or on a virtual computer (also referred to as a “Virtual Machine”).</Text><Text id="56505" page="17">Note that a rugged / industrial computer built on the Intel / AMD CPU architecture, and running the Operating Systems mentioned above, are also considered a “Computer”.</Text><Text id="56506" page="17">Conduit A conduit regulates communication between one or more devices in the same security zone or different security zones. A conduit within a security zone could be the control center LAN. A conduit between two zones could be the WAN connection between the primary and backup control centers. Conduits can be trusted or untrusted. Each conduit is assigned a security level.</Text><Text id="56507" page="17">From IEC62443-1-1 (chap 10.2.3): Information must flow into, out of, and within a security zone. Even in a non-networked system, some communication exists (e.g., intermittent connection of programming devices to create and maintain the systems). To cover the security aspects of communication and to provide a construct to encompass the unique requirements of communications, this standard is defining a special type of security zone: a communications conduit.</Text><Text id="56508" page="18">Note that Windows CE (Compact Embedded), or Windows loT Core, are not considered general-purpose Operating Systems. Components running these operating systems (typically local HMI Panels) are considered “Devices”.</Text><Text id="56509" page="18">ÿÿÿÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿÿ ÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿÿÿ ÿÿÿÿÿÿ ÿ ÿÿÿ ÿÿ ÿÿÿ ÿ ÿÿÿ ÿÿÿ ÿ ÿÿÿÿÿÿÿÿÿÿÿ ÿ ÿÿ ÿ ÿÿÿÿ ÿÿÿ ÿÿÿÿÿÿ ÿÿ ÿ ÿÿÿÿÿ ÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿ ÿ ÿ ÿÿÿÿ ÿÿÿÿ ÿÿÿ ÿÿÿÿÿ ÿ ÿÿÿ ÿÿÿ ÿÿÿ ÿÿÿÿÿÿÿÿÿÿÿÿ ÿÿ ÿÿ ÿÿ ÿÿÿÿÿ ÿÿ ÿÿÿÿÿ ÿ ÿÿÿÿÿÿ ÿÿÿ ÿ ÿ ÿ ÿ ÿ ÿÿÿ ÿÿÿ ÿÿ ÿÿÿ ÿÿÿ ÿÿ ÿÿ ÿÿ ÿÿ ÿ ÿÿ ÿÿ ÿÿÿ ÿÿÿ ÿÿ ÿ ÿÿ ÿÿ ÿ ÿÿ ÿÿÿ ÿ ÿÿÿÿÿÿÿÿÿ ÿÿÿÿ ÿ ÿÿÿÿÿÿÿ ÿÿÿÿ ÿÿ ÿ ÿÿ ÿ ÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿÿ ÿ ÿÿ ÿ ÿÿÿÿÿÿ ÿÿÿÿÿÿÿÿ ÿÿÿ ÿÿÿ ÿ ÿÿÿ ÿÿ ÿ ÿÿÿ ÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿ ÿÿ ÿÿ ÿÿÿÿÿÿ ÿÿÿÿ ÿÿÿÿÿ ÿÿ ÿÿ ÿÿ ÿÿÿÿÿÿÿ ÿÿÿÿÿ ÿ ÿÿÿÿ ÿÿÿÿÿ ÿ ÿÿ ÿÿÿÿÿÿ ÿ ÿÿÿÿÿÿ ÿ ÿ</Text><Text id="56510" page="18">A conduit can be a single service (i.e., a single Ethernet network) or can be made up of multiple data carriers (multiple network cables and direct physical accesses). As with zones, it can be made of both physical and logical constructs. Conduits may connect entities within a zone or may connect different zones.</Text><Text id="56511" page="18">As with zones, conduits may be either trusted or untrusted. Conduits that do not cross zone boundaries are typically trusted by the communicating processes within the zone. Trusted conduits crossing zone boundaries must use an end-to- end secure process.</Text><Text id="56512" page="18">Distribution network layer The distribution layer aggregates the uplinks from the edge (also called access) layer to the core network layer. See &quot;Network distribution switch&quot;.</Text><Text id="56513" page="18">Untrusted conduits are those that are not at the same level of security as the zone endpoint. In this case the security of the communication becomes the responsibility of the individual channel. Further information on this scenario is available in the Annex.</Text><Text id="56514" page="18">A conduit regulates communication between one or more devices in the same security zone or different security zones. A conduit within a security zone could be the control center LAN. A conduit between two zones could be the WAN connection between the primary and backup control centers. Conduits can be trusted or untrusted. Each conduit is assigned a security level.</Text><Text id="56515" page="18">Data Representation of facts, concepts, or instructions in a manner suitable for communication, interpretation, or processing by humans or by automatic means. (Source: ISO/IEC/IEEE 24765:2017).</Text><Text id="56516" page="18">Data link Means of connecting one networked device to another for the purpose of transmitting and receiving digital information.</Text><Text id="56517" page="18">Devices Devices, also referred to as “Embedded Devices”, are components such as (but not limited to) PLCs, VSD controllers, Motor starters, Thyristor controllers, Flow computers, lEDs, Serial servers, Communication devices, Advanced analysers etc.</Text><Text id="56518" page="18">A “Device” is basically any configurable I programmable Component which is not considered a “Computer” or “Network Equipment”.</Text><Text id="56519" page="18">End user In product development, an end user (sometimes end-user) is a person who ultimately uses or is intended to ultimately use a product. The end user stands in contrast to users who support or maintain the product.</Text><Text id="56520" page="18">Engineering Work Station The maintenance stations for industrial control systems where system management and application software engineering,</Text><Text id="56523" page="18">Firewall A network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. A firewall typically establishes a barrier between a trusted internal network and untrusted external network. (Source; Wikipedia)</Text></Spec>