International (IEC TC 57 WG15); adopted as EN IEC 62351

IEC 62351

109 controls. 290 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

109 controls 290 frameworks share controls with it International (IEC TC 57 WG15); adopted as EN IEC 62351 verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

IEC 62351 Power Systems Communication Security Evidence & Implementation Kit

109 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
62351-10Security architecture guidelines9
62351-11Security for XML documents0
62351-12Resilience and security recommendations for DER55
62351-13Cyber-physical generation and storage resilience55
62351-14Cyber security event logging65
62351-2Glossary of terms169
62351-3Profiles including TCP/IP0
62351-4Profiles including MMS and similar payloads0
62351-5Security for IEC 60870-5 and derivatives0
62351-6Security for IEC 61850 profiles0
62351-7Network and system management (NSM)0
62351-8Role-based access control (RBAC)155
62351-9Cyber security key management138
IEC62351-10Security Architecture0
IEC62351-100Conformance Testing0
IEC62351-11XML File Security0
IEC62351-12Resilience for DER and Substation Automation0
IEC62351-13Guidelines on Security Topics0
IEC62351-14Cybersecurity Event Logging0
IEC62351-3TLS for TCP/IP Profiles0
IEC62351-4MMS and IEC 61850 Application Security0
IEC62351-5IEC 60870-5 and DNP3 Secure Authentication0
IEC62351-6IEC 61850 GOOSE and SV Security0
IEC62351-7Network and System Management0
IEC62351-8Role-Based Access Control0
IEC62351-9Cybersecurity Key Management0
IEC62351-CERTCertificate Lifecycle for Substations0
IEC62351-ICCPICCP/TASE.2 Secure Bilateral0
IEC62351-IRIncident Response for Substations0
IEC62351-MONSecurity Monitoring of Substation Networks0
IEC62351-PATCHPatch and Vulnerability Management for OT0
IEC62351-SEGSegmentation of Process and Station Buses0
IEC62351-SUPSupplier Security Requirements0
100-6:4Part 100-6, clause 4: conformance test methodology for IEC 62351-6 (environment, normal and resiliency tests, device under test, test facility, validation, PICS and PIXIT, test cas0
100-6:5Part 100-6, clauses 5 and 6: GOOSE and SV security conformity testing and SCL extension testing0
10:4Part 10, clause 4: power system specifics, related standardization and the TC 57 reference architecture0
10:5Part 10, clause 5: security architecture in power systems (security domains and their mapping, system interface categories, security controls and their domain mapping, determinatio0
10:6Part 10, clause 6: mapping security controls to the TC 57 architecture and to scenarios (substation automation, control centre to substation, advanced metering) and identified gaps0
11:XMLPart 11: security for XML files (source authentication, tamper detection, compatibility with CIM and SCL formats)0
3:10Part 3, clause 10: conformance to selected TLS versions, certificate handling and version-specific requirements0
3:4Part 3, clause 4: security issues addressed, threats and attack methods countered, security events0
3:6.2Part 3, 6.2: signalling of supported TLS versions0
3:6.3Part 3, 6.3: usage of non-encrypting cipher suites0
3:6.4Part 3, 6.4: certificate support (multiple trust anchors, certificate size, exchange, validation)0
3:6.5Part 3, 6.5: co-existence with non-secure protocol traffic0
3:7.2Part 3, 7.2 and 7.3: TLSv1.2 supported and disallowed cipher suites0
3:7.4Part 3, 7.4: TLSv1.2 key exchange, algorithms, session resumption and renegotiation0
3:7.5Part 3, 7.5: TLSv1.2 extensions (renegotiation indication, trusted CA, signature algorithms, OCSP stapling, server name indication, encrypt-then-MAC)0
3:8.2Part 3, 8.2 and 8.3: TLSv1.3 cipher suites, handshake modes, Diffie-Hellman groups and signature algorithms0
3:8.4Part 3, 8.4 to 8.7: TLSv1.3 session key update, new session ticket, session resumption and certificate validation0
3:8.8Part 3, 8.8: TLSv1.3 extensions (supported versions, cookie, signature algorithms, supported groups, key share, server name indication, certificate authorities, PSK key agreement, 0
3:9Part 3, clause 9: optional security measure support0
4:10Part 4, clauses 9 and 10: object identifier allocation and general OSI upper layer requirements (session, presentation, ACSE)0
4:11Part 4, clause 11: the A-security profile (ACSE authentication with the MMS authentication value)0
4:12Part 4, native mode end-to-end application security (protected PDUs, association management, session keys)0
4:4Part 4, clause 4: communications reference models, application and transport security profiles, compatibility and native modes, threats and attacks countered0
4:5Part 4, clause 5: specific requirements for the ICCP (IEC 60870-6) stack and for IEC 618500
4:6Part 4, clause 6: transport security (TLS application, cipher suites, session resumption and renegotiation, trust anchors, certificate size, revocation evaluation period, certifica0
4:8Part 4, clause 8: use of cryptographic algorithms (public-key, hash, signature, symmetric encryption, authenticated encryption, integrity check value)0
5:5.2Part 5, 5.2: threats addressed (spoofing, tampering, replay, eavesdropping)0
5:5.3Part 5, 5.3: design issues of the telecontrol environment0
5:5.4Part 5, 5.4: general principles (application layer only, generic definition mapped to protocols, bi-directional, key management, backwards tolerance, upgradeable, multiple connecti0
5:6.2Part 5, 6.2: theory of operation (association ID, authenticating, central authority, role-based access control, cryptographic keys, security statistics and events)0
5:7Part 5, clause 7: functional requirements (procedures, state machines, timers and counters, security statistics thresholds, reporting, event monitoring and logging)0
5:8.3Part 5, 8.3: station association procedure (public-key certificates, configuration of authorized remote stations, verification of certificates, update keys)0
5:8.4Part 5, 8.4: session key change procedure0
5:8.5Part 5, 8.5 and following: authentication of critical messages (challenge-response and aggressive mode), ASDU protection and error handling0
6:10Part 6, clause 10: extension of the LGOS and LSVS logical nodes0
6:11Part 6, clause 11: conformance (general, IEC 61850-8-1 profiles, VLAN profiles, SNTP profile) with PICS tables0
6:4Part 6, clause 4: operational issues, threats and attacks countered for IEC 61850 profiles0
6:5Part 6, clause 5: correlation of IEC 61850 and IEC 62351 parts (MMS security profiles, VLAN profiles, IEC 61850-8-2, OriginatorID binding)0
6:6Part 6, clause 6: multicast association protocols and replay protection for GOOSE and Sampled Values0
6:7Part 6, clause 7: security for SNTP0
6:8Part 6, clause 8: the extended PDU for GOOSE and SV (Ethertype, extension octets, calculated MAC domain, AES-GCM)0
6:9Part 6, clause 9: substation configuration language extensions (access point security capability, publish with security enabled, key policy and management, simulation)0
7:MONPart 7 in use: monitoring of the information infrastructure with NSM objects0
7:NSMPart 7: network and system management data objects for the power system information infrastructure0
8:10Part 8, clause 10: RBAC access token distribution models0
8:5Part 8, clause 5: the RBAC process model and concepts (subjects, roles, permissions, separation, criteria for defining roles)0
8:6Part 8, clause 6: pre-defined roles, role-to-permission assignment, custom roles, operational states and security events0
8:7Part 8, clause 7: simplified role assignment (generic roles across multiple role definitions)0
8:8Part 8, clause 8: definition of access tokens (mandatory and optional components, profiles A X.509 public-key certificate, B X.509 attribute certificate, C JSON Web Token, D RADIUS0
8:9Part 8, clause 9: verification of access tokens (multiple tokens, subject authentication, availability, validity period, integrity, issuer, role ID, revision, area of responsibilit0
90-3:5Part 90-3, clause 5: information collection, filtering and processing (IT and OT elements, SNMP agents, IDS and IPS probes, central NSM platforms, log collection, log agents, norma0
90-3:6Part 90-3, clause 6: information correlation and presentation (collection profiles for NSM and part 7, IEC 61850-specific monitoring, other SNMP objects, logs; events, incidents an0
90-3:7Part 90-3, clauses 7 and 8: monitoring use cases (substation, DER systems, large hydro, generation) and monitoring profiles for attack scenarios (malicious IED program change, unex0
9:4Part 9, clause 4: security concepts applicable to power systems (confidentiality, integrity, authentication, non-repudiation; cryptographic algorithms and concepts)0
9:5.2Part 9, 5.2 to 5.5: key management lifecycle, key usages, key management system security policy and design principles for power system operations0
9:5.6Part 9, 5.6: key agreement (Diffie-Hellman, key derivation functions, group key management)0
9:5.7Part 9, 5.7: public-key and privilege management infrastructures (registration and certification authorities, public-key certificates, attribute certificates, extensions)0
9:5.8Part 9, 5.8: certificate management (process, initial creation, onboarding, enrolment, CSR processing, enrolment protocols, trust anchor management)0
9:5.9Part 9, 5.9 to 5.11: revocation (CRL, OCSP, SCVP, recovery), trust via self-signed certificates, authorization and validation lists0
9:6Part 9, clause 6: normative key management requirements (security events, required cryptographic material, random number generation, object identifiers)0
9:7Part 9, clause 7: asymmetric key management (certificate components, generation and installation, key protection, certificate policy, trust anchor establishment and update, entity 0
9:8Part 9, clause 8: symmetric key management (group keys for GOOSE, SV and PTP through GDOI; session keys for IEC 60870-5 and DNP3)0
OTHER-PARTSParts not held: 2 glossary, 12 DER resilience, 13 security topics for standards, 14 event logging, 90-1, 90-2, 100-1, 100-3, 100-40
PART-1IEC TS 62351-1:2007: introduction to security issues for the series0
PART-10IEC 62351-100
PART-100-6IEC 62351-100-60
PART-11IEC 62351-110
PART-3IEC 62351-30
PART-4IEC 62351-40
PART-5IEC 62351-50
PART-6IEC 62351-60
PART-7IEC 62351-70
PART-8IEC 62351-80
PART-9IEC 62351-90
PART-90-3IEC 62351-90-30
SERIESIEC 62351: the series, its parts and what is held0

Tell me when IEC 62351 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Network architecture diagram
  • Firewall rule sets
  • Zone-conduit register
  • DMZ design
  • Network diagrams
  • Zone and conduit document
  • SIEM deployment and coverage
  • Baseline of normal activity
  • Alerting and triage records
  • SNMP/IEC 61850 NSM mapping

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for IEC 62351, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition