GB/T 36323-2018 in English
VALIDInformation security technology--Security management fundamental requirements for industrial control systems
- Issued on:2018-06-07
- Implemented on:2019-01-01
- File Format:PDF
- Delivery:Via email within 5 business days
$612.00
《GB/T 36323-2018信息安全技术 工业控制系统安全管理基本要求》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Core framework of industrial control system security management standards
The standard builds a security management system that includes DCS, SCADA, PLC and other systems, and forms a closed-loop management through six key activities such as top-level commitment, planning and evaluation.
Classification system of security control measures
| Control category | Typical measures | Coverage dimensions |
|---|---|---|
| Management system | Security assessment (CA), system acquisition (SA) | 4 control families |
| Operation and maintenance management | Media protection (MP), incident response (IR) | 9 control families |
| Technical management | Access control (AC), identification authentication (IA) | 3 control families |
Key points for the implementation of key control measures
Physical and Environmental Security (PE)
Emergency Power Off (PE-9) requires the installation of an independent power switch, and the fourth-level system needs to add protection against misoperation. Taking a chemical plant as an example, a dual-channel UPS + diesel generator combination is deployed in the DCS control room to meet the PE-10 emergency power supply requirements.
Access Control (AC)
Systems above level 3 must implement multi-factor authentication (IA-2), such as a power grid SCADA system uses a two-factor authentication of smart card + dynamic password.
Differentiated security level requirements
Appendix A divides control measures into four levels:
- Level 1: Basic requirements, such as CA-2 security assessment must include three items a)~c)
- Level 4: Enhanced requirements, such as CA-6 continuous monitoring must achieve seven items a)~g)
Implementation recommendations
- Establish a cross-departmental ICS security joint management team (5.2.3)
- Prioritize the implementation of CA-3 connection management and AC-9 remote access control
- Refer to Appendix A to tailor control measures

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 20009-2019 in English
Information security technology—Security evaluation criteria for database management system
2019-08-30 -

GB/T 29767-2013 in English
Information security techniques—Public key infrastructure—Bridge Certification Authority leveled certificate specification
2013-09-18 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 24363-2009 in English
Information security technology—Specifications of emergency response plan for information security
2009-09-30 -

GB/T 25056-2018 in English
Information security technology—Specifications of cryptograph and related security technology for certificate authentication system
2018-06-07 -

GB/T 40018-2021 in English
Information security technology—Certificate request and application protocol based on multiple channels
2021-04-30