GB/T 40211-2021 in English
VALIDIndustrial communication networks - Network and system security - Terminology, concepts and models
- Issued on:2021-05-21
- Implemented on:2021-12-01
- File Format:PDF
- Delivery:Via email within 5 business days
$1,164.00
| Standard No: | GB/T 40211-2021 |
| Document status: | VALID |
| Title in English: | Industrial communication networks - Network and system security - Terminology, concepts and models |
| Title in Chinese: | 工业通信网络 网络和系统安全 术语、概念和模型 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 5 business days |
| Issued on: | 2021-05-21 |
| Implemented on: | 2021-12-01 |
| ICS Classification: | 25.040-Industrial automation systems |
| Chinese Classification: | N10-Industrial automation and control device in general |
| Professional Classification: | GB-National Standard |
| Related Keywords: | industrial communication network security standards
system security control network depth security model layered protection system physical layer enterprise network |
| Related Topics: | Three-level network model
network gb gb network Industrial communication network network and system security terms, concepts and models GBT40211 GB/T 40211-2021 Model Development General Conceptual Model |
《GB/T 40211-2021工业通信网络 网络和系统安全 术语、概念和模型》由TC124(全国工业过程测量控制和自动化标准化技术委员会)归口,主管部门为中国机械工业联合会。
Introduction
Core Framework of Industrial Communication Network Security Standards
This standard is equivalent to IEC/TS 62443-1-1:2009, and builds the basic terminology system and conceptual model for industrial automation and control system (IACS) security. By defining key concepts such as safety zone and pipeline, it provides a structured methodology for risk assessment and security protection.
Key Terms and Security Goals
| Terms | Definition | Industrial Scenario Priorities |
|---|---|---|
| Availability | The ability of a system to continuously provide services under specified conditions | Highest (Level 1) |
| Integrity | Prevent unauthorized data tampering | Second highest (Level 2) |
| Confidentiality | Prevent information leakage | Basic (Level 3) |
Note: Unlike traditional IT systems, industrial control systems prioritize process continuity, and the target priority is reversed in typical scenarios.
Defense in Depth Security Model
Layered Protection System
- Physical Layer: Device Access Control and Environmental Protection
- Network Layer: Firewall, Network Segmentation and Intrusion Detection
- System Layer: Host Hardening and Malicious Code Protection
- Application Layer: Permission Management and Data Encryption
Typical Case: A petrochemical enterprise established a DMZ isolation zone between the control network and the enterprise network by dividing the security zone to achieve controlled filtering of network communications.
Security Level Lifecycle Management
| Phases | Core Tasks | Outputs |
|---|---|---|
| Assessment | Asset Identification and Risk Analysis | STarget Level |
| Implementation | Countermeasures Deployment | SAchieved Level |
| Maintenance | Continuous Monitoring and Upgrades | Audit Report |
Note: Security capabilities (Scapability) need to be verified regularly to ensure that the protection requirements of Starget ≥ Sachievement are always met.
Standard evolution and industry impact
The technical framework of this standard is derived from the IEC 62443 series, reflecting the security challenges in the transformation of industrial control systems from closed and dedicated to open and interconnected. Main enhancements of the 2021 version:
- Clarify the security interaction requirements between Safety Instrumented Systems (SIS) and basic control systems
- Supplement the security management clauses for wireless devices and IoT terminals
- Refine the security program maturity assessment indicators
Implementation suggestions: Enterprises should establish a cross-departmental CSMS (cybersecurity management system), integrate IT and OT security strategies, and refer to Chapter 5.8 of this standard to develop a phased implementation plan.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 47014.3-2026 in English
Industrial communication networks—Fieldbus specifications—Type 2 elements: EtherNet/IP,ControlNet and DeviceNet specifications—Part 3: Applicatoin layer service definition
2026-01-28 -

GB/T 27960-2011 in English
Ethernet POWLINK communication profile specification
2011-12-30 -

GB/T 32235.2-2024 in English
Industrial process measurement, control and automation—Digital factory framework—Part 2: Model elements
2024-08-23 -

GB/T 41157.3-2022 in English
Fasteners for nuclear power plants—Part 3:Bolts, screws and studs made of corrosion-resistant stainless steel
2022-03-09 -

GB/T 19582.1-2008 in English
Modbus industrial automation network specification - Part 1: Modbus application protocol
2008-02-27 -

GB/T 32857-2025 in English
Application directives for layer of protection analysis(LOPA)
2025-12-02 -

GB/Z 21099.6-2018 in English
Function blocks(FB) for process control and electronic device description language(EDDL)—Part 6:Meeting the requirements for integrating fieldbus devices in engineering tools for field devices
2018-06-07 -

GB/T 41771.11-2025 in English
Field device integration—Part 11: Profiles—PROFIBUS
2025-10-31