No safety without security

Cyber security is an increasing threat. It has expanded from its origins in the home and office PC environment into Industrial Control Systems. Here Peter Sieber of HIMA explains that only by looking at a wider solution, through a combination of functional safety and IT security, can businesses truly ensure their overall safety

Safety-related automation solutions must not only provide functional safety, they also need to ensure cyber security. Only the combination of functional safety and information security ensures the overall safety of the plant. Even ruling out malicious threats, the fact remains that IT security vulnerabilities can be found in almost any kind of automation system. This includes the safety-related system itself and the distributed control system (DCS), of which the safety system may be a part. This is one reason why many safety experts call not only for the physical separation of Safety Instrumented System (SIS) and DCS components, but also for different engineering staffs and/or vendors to be responsible for each.

International standards 

IEC 61508 is the international standard of rules for the functional safety of electrical, electronic, and programmable electronic safety-related systems. Furthermore, there is international standard IEC 61511 for the SIS. Whether independent or integrated into an overall basic process control system (BPCS), the SIS is a fundamental component of every industrial process facility. 

In accordance with IEC 61511 (see illustration top right), the first line of protection for any plant is the control and monitoring layer, which includes the basic process control system (BPCS). The BPCS reduces the risk of the occurrence of an unwanted event. The prevention layer includes the SIS. The hardware and software at this level perform individual Safety Instrumented Functions (SIFs). To reduce the overall risk to an acceptable level, the majority of critical industrial processes require an SIS that fulfils the requirements of Safety Integrity Level 3 (SIL 3). 

At the mitigation layer, technical systems are required to reduce damage should the inner protection layers fail. Mitigation systems are not usually encountered as part of the safety system. This is because they are only activated after the occurrence of an event (that should have been prevented). Mechanical equipment or structural features are often used in mitigation systems. Examples include retention basins or automatic fire suppression systems.

Protection from cyber-attacks

The IEC standard for cybersecurity IEC 62443, which is currently in draft form, covers the necessary security techniques to prevent cyber-attacks on facility networks and systems. It contains seven foundational requirements. These consider the various security objectives, such as protecting a system against unauthorised access. IEC 62443 also covers the protection of networks within automation systems. 

As indicated by figure 2, it requires the separation of the overall system. It also introduces the concept of security zones, defined conduits, and additional firewalls at every conduit that connects one security zone to another one with different requirements. This structure creates a tiered system of different defence mechanisms (also known as defence in depth).The firewalls have different technical requirements depending on which security level each zone requires.

Standards and structures

According to the most recent version of IEC 61511, both organisational demands and physical structures equally need to be protected. The standard calls for the following: Carry out a security risk assessment of the SIS; Make the SIS sufficiently resilient against the identified security risks; Safeguard the performance of the SIS, error detection and correction, protection against unwanted program alterations, protection of data for troubleshooting the SIF, and protection against bypassing restrictions to prevent the deactivation of alarms and manual shutdown; Enable/disable read/write access via a sufficiently secure method.

In terms of structural requirements, IEC 61511 instructs plant operators to conduct an assessment of their SIS. They should: Ensure independence between protection layers; Establish diversity between protection layers; Physical separate protection layers; Identify and avoid common-cause failures between protection layers. In fact, the IEC 61511 and IEC 62443 standards both demand independent protection layers.

IPE Newsletter

IPE publishes a weekly eNewsletter, delivering a carefully chosen selection of the latest stories straight to your inbox.

Subscribe here