Valid

GB/T 40211-2021Industrial communication networks - Network and system security - Terminology, concepts and models (English PDF)

Also coversGBT40211-2021

Open the GB/T 40211-2021 preview as PDF

Preview — first pages of GB/T 40211-2021

This is a limited preview

Buy now to download the full PDF

Issued by

State Administration for Market Regulation, China National Standardization Administration

Level / Type

National · Recommended

Issue date

May 21, 2021

Implementation date

December 1, 2021

Scope

GB/T 40211-2021 (Industrial communication networks - Network and system security - Terminology, concepts and models) is available as an English-translated PDF.

GB/T 40211-2021 — This standard is a technical specification that defines the terms, concepts and models used for industrial automation and control system (IACS) security. It is a series of standards. The basis of other standards in the standard. In order to fully and clearly express the systems and components of this standard, the scope of coverage can be defined and understood from several aspects, including.

Document preview — GB/T 40211-2021

National Standard of the People's Republic of China

Classification
N 10

Issued by: State Administration for Market Regulation, China National Standardization Administration

Contents

  • 1 Scope1
  • 1.1 Overview1
  • 1.2 Included functionality1
  • 1.3 System and interface1
  • 1.4 Activity-based criteria2
  • 1.5 Asset-based guidelines2
  • 2 Normative references2
  • 3 Terms and definitions, abbreviations3
  • 3.1 Overview3
  • 3.2 Terms and definitions3
  • 3.3 Abbreviations16
  • 4 Status Quo17
  • 4.1 Overview17
  • 4.2 Current system18
  • 4.3 Current trends18
  • 4.4 Potential impact18
  • 5 Concept19
  • 5.1 Overview19
  • 5.2 Safety objectives19
  • 5.3 Basic requirements20
  • 5.4 Defense in Depth20
  • 5.5 Security Context20
  • 5.6 Threat-Risk Assessment22
  • 5.7 Safety program maturity28
  • 5.8 Strategy33
  • 5.9 Safe Zone37
  • 5.10 Piping38
  • 5.11 Security level39
  • 5.12 Safety level life cycle43
  • 6 Model46
  • 6.1 Overview46
  • 6.2 Reference model47
  • 6.3 Asset Model50
  • 6.4 Reference Architecture54
  • 6.5 Zone and pipe model54
  • 6.6 Relationship Between Models63
  • Reference65

Foreword

This standard was drafted in accordance with the rules given in GB/T 1.1-2009.

The translation method used in this standard is equivalent to IEC /T S62443-1-1.2009 "Industrial Communication Network Network and System Security Part 1-1

Sub. Terminology, Concept and Model.

The Chinese documents that have a consistent correspondence relationship with the normatively cited international documents in this standard are as follows.

---GB/T 18336.1-2015 Information Technology Security Technology Information Technology Security Assessment Criteria Part 1.Introduction and One

General model (ISO /IEC 15408-1.2009, IDT)

---GB/T 20720.1-2019 Enterprise Control System Integration Part 1.Model and Terminology (IEC 62264-1.2013, IDT)

This standard has made the following editorial changes.

---Modified the standard name.

This standard was proposed by the China Machinery Industry Federation.

This standard is under the jurisdiction of the National Industrial Process Measurement Control and Automation Standardization Technical Committee (SAC/TC124).

Drafting organizations of this standard. Institute of Comprehensive Technology and Economics of Machinery Industry Instrumentation, Central Electric Power Planning Institute Co., Ltd., China Nuclear Power Engineering

Co., Ltd., Hollysys Technology Group Co., Ltd., Beijing Water Supply Group Co., Ltd., Zhejiang University, Huazhong University of Science and Technology, Chongqing

University of Posts and Telecommunications, Computer and Microelectronics Development Research Center of the Ministry of Industry and Information Technology (China Software Evaluation Center), Siemens (China) Co., Ltd.

Division, Schneider Electric (China) Co., Ltd., Rockwell Automation (China) Co., Ltd., Shenyang Institute of Automation, Chinese Academy of Sciences, Beijing

Venus Star Information Security Technology Co., Ltd., Beijing Guodian Zhishen Control Technology Co., Ltd., Shenzhen Wanxun Automation Control Co., Ltd., China

The 30th Research Institute of Electronic Technology Group Corporation, the Fifth Research Institute of Electronics of the Ministry of Industry and Information Technology, Southwest University, China Dongfang Electric Group Co., Ltd.

Company, Beijing Sifang Relay Automation Co., Ltd., National Industrial Information Security Development Research Center, Beijing Rail Transit Design and Research

Institute Co., Ltd., Shanghai Automation Instrumentation Co., Ltd., Chongqing Xin'an Network Security Rating and Evaluation Co., Ltd., the Third Research Institute of the Ministry of Public Security, China

Network Security Review Technology and Certification Center, Beijing Wangyu Nebula Information Technology Co., Ltd.

Introduction

The subject of this standard is the safety of industrial automation and control systems. In order to be applicable to different applications (e.g. industry types), each term

Both have a broad interpretation.

The term "industrial automation and control system" (IACS) includes control systems used in manufacturing and process industries, building control systems,

Geographically dispersed operations such as public facilities (e.g. electricity, natural gas and water supply), pipelines and oil production and distribution facilities, other industries and

Applications such as transportation networks, those that use automated or remotely controlled or monitored assets.

The term "safety" in this standard refers to the prevention of illegal or harmful infiltration, intentional or unintentional obstruction of normal and expected operation, or failure to

Appropriate access to the confidential information of IACS. Computer security that this standard pays special attention to, including computers, networks, operating systems, applications and systems

Other programmable components of the system.

The readers of this standard include all IACS users (including part of the facility operation, maintenance, construction and user organization), production

Affected, control system computer security, control system practitioners, and security practitioners, including operators, suppliers, and government organizations. Because of the letter

Mutual understanding and cooperation between information technology (IT) and operators, engineering personnel, and manufacturers' organizations are essential for any information initiative to achieve comprehensive

Success is very important. This standard is also a reference for those responsible for IACS and enterprise network integration.

This standard mainly involves the following typical issues.

a) What is the scope of IACS security application?

b) How to use uniform terminology to define the needs and requirements of the safety system?

c) What basic concepts are used as the basis for further analysis of activities, system attributes and actions, which provide electronic security control

Is very important for the control system?

d) How to group or classify IACS components for use in defining and managing security?

e) What are the different safety goals in control system applications?

f) How were these goals established and modified?

Each issue is described in detail in this standard.

Industrial communication network network and system security

Terminology, concepts and models

1 Scope

1.1 Overview

This standard is a technical specification that defines the terms, concepts and models used for industrial automation and control system (IACS) security. It is a series of standards.

The basis of other standards in the standard.

In order to fully and clearly express the systems and components of this standard, the scope of coverage can be defined and understood from several aspects, including.

---The scope of functionality contained;

---Specific systems and interfaces;

---Criteria for selecting the included activities;

---Criteria for the selection of included assets.

The following sections are an introduction to these contents.

1.2 Included functionality

The scope of this standard can be described as the scope of functionality within organizational information and automation systems. The functionality can typically be one or

More models to describe.

This standard mainly focuses on industrial automation and control, which is described in the reference model (see Chapter 6). Although the business department is considered

Data integrity exchanges between industrial systems and industrial systems, business plans and logistics systems are not within the scope of this standard.

Industrial automation and control include the typical and common monitoring and control components in the process industry. Also includes SCADA (Supervision and Data Acquisition

Set), the system is often used by organizations to operate critical infrastructure. include.

---Transformation and distribution of electricity;

---Gas and water supply pipe network;

---Oil and gas production and operation;

---Gas and liquid transmission pipelines.

In addition, SCADA systems can also be applied to other critical and non-critical infrastructures.

1.3 System and interface

In all the included IACS, the standard covers the functional safety, safety and safety of the system that may change or affect the industrial process.

Rely on operation. These include but are not limited to.

a) Industrial control systems and related communication networks, including distributed control systems (DCS), programmable logic controllers (PLC), remote

Process terminal unit (RTU), intelligent electronic equipment, SCADA system, networked electronic sensing and control, metering and pipeline transmission system

Systems and monitoring and diagnostic systems [In this standard, industrial control systems include basic process control systems and safety instrumented systems

(SIS), regardless of whether they are physically separated or integrated].

b) Systems related to layer 3 or lower in the reference model described in Chapter 6.Such as advanced or multi-variable control, online optimization

Monitors, dedicated equipment monitors, graphical interfaces, process history records, production execution systems, pipeline leak detection systems, work management,

Power outage management and electric energy management system.

c) Used to provide control, functional safety, production or remote operation functions to achieve continuous, batch, discrete and other process related internal

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — all pages — is available in the English PDF.

Referenced standards

How to Buy GB/T 40211-2021

  1. 1Add to cart. Click the "Buy GB/T 40211-2021" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 40211-2021

$1,190.00

$1,010.00for partners