62351-10 | Security architecture guidelines | 9 |
62351-11 | Security for XML documents | 0 |
62351-12 | Resilience and security recommendations for DER | 55 |
62351-13 | Cyber-physical generation and storage resilience | 55 |
62351-14 | Cyber security event logging | 65 |
62351-2 | Glossary of terms | 169 |
62351-3 | Profiles including TCP/IP | 0 |
62351-4 | Profiles including MMS and similar payloads | 0 |
62351-5 | Security for IEC 60870-5 and derivatives | 0 |
62351-6 | Security for IEC 61850 profiles | 0 |
62351-7 | Network and system management (NSM) | 0 |
62351-8 | Role-based access control (RBAC) | 155 |
62351-9 | Cyber security key management | 138 |
IEC62351-10 | Security Architecture | 0 |
IEC62351-100 | Conformance Testing | 0 |
IEC62351-11 | XML File Security | 0 |
IEC62351-12 | Resilience for DER and Substation Automation | 0 |
IEC62351-13 | Guidelines on Security Topics | 0 |
IEC62351-14 | Cybersecurity Event Logging | 0 |
IEC62351-3 | TLS for TCP/IP Profiles | 0 |
IEC62351-4 | MMS and IEC 61850 Application Security | 0 |
IEC62351-5 | IEC 60870-5 and DNP3 Secure Authentication | 0 |
IEC62351-6 | IEC 61850 GOOSE and SV Security | 0 |
IEC62351-7 | Network and System Management | 0 |
IEC62351-8 | Role-Based Access Control | 0 |
IEC62351-9 | Cybersecurity Key Management | 0 |
IEC62351-CERT | Certificate Lifecycle for Substations | 0 |
IEC62351-ICCP | ICCP/TASE.2 Secure Bilateral | 0 |
IEC62351-IR | Incident Response for Substations | 0 |
IEC62351-MON | Security Monitoring of Substation Networks | 0 |
IEC62351-PATCH | Patch and Vulnerability Management for OT | 0 |
IEC62351-SEG | Segmentation of Process and Station Buses | 0 |
IEC62351-SUP | Supplier Security Requirements | 0 |
100-6:4 | Part 100-6, clause 4: conformance test methodology for IEC 62351-6 (environment, normal and resiliency tests, device under test, test facility, validation, PICS and PIXIT, test cas | 0 |
100-6:5 | Part 100-6, clauses 5 and 6: GOOSE and SV security conformity testing and SCL extension testing | 0 |
10:4 | Part 10, clause 4: power system specifics, related standardization and the TC 57 reference architecture | 0 |
10:5 | Part 10, clause 5: security architecture in power systems (security domains and their mapping, system interface categories, security controls and their domain mapping, determinatio | 0 |
10:6 | Part 10, clause 6: mapping security controls to the TC 57 architecture and to scenarios (substation automation, control centre to substation, advanced metering) and identified gaps | 0 |
11:XML | Part 11: security for XML files (source authentication, tamper detection, compatibility with CIM and SCL formats) | 0 |
3:10 | Part 3, clause 10: conformance to selected TLS versions, certificate handling and version-specific requirements | 0 |
3:4 | Part 3, clause 4: security issues addressed, threats and attack methods countered, security events | 0 |
3:6.2 | Part 3, 6.2: signalling of supported TLS versions | 0 |
3:6.3 | Part 3, 6.3: usage of non-encrypting cipher suites | 0 |
3:6.4 | Part 3, 6.4: certificate support (multiple trust anchors, certificate size, exchange, validation) | 0 |
3:6.5 | Part 3, 6.5: co-existence with non-secure protocol traffic | 0 |
3:7.2 | Part 3, 7.2 and 7.3: TLSv1.2 supported and disallowed cipher suites | 0 |
3:7.4 | Part 3, 7.4: TLSv1.2 key exchange, algorithms, session resumption and renegotiation | 0 |
3:7.5 | Part 3, 7.5: TLSv1.2 extensions (renegotiation indication, trusted CA, signature algorithms, OCSP stapling, server name indication, encrypt-then-MAC) | 0 |
3:8.2 | Part 3, 8.2 and 8.3: TLSv1.3 cipher suites, handshake modes, Diffie-Hellman groups and signature algorithms | 0 |
3:8.4 | Part 3, 8.4 to 8.7: TLSv1.3 session key update, new session ticket, session resumption and certificate validation | 0 |
3:8.8 | Part 3, 8.8: TLSv1.3 extensions (supported versions, cookie, signature algorithms, supported groups, key share, server name indication, certificate authorities, PSK key agreement, | 0 |
3:9 | Part 3, clause 9: optional security measure support | 0 |
4:10 | Part 4, clauses 9 and 10: object identifier allocation and general OSI upper layer requirements (session, presentation, ACSE) | 0 |
4:11 | Part 4, clause 11: the A-security profile (ACSE authentication with the MMS authentication value) | 0 |
4:12 | Part 4, native mode end-to-end application security (protected PDUs, association management, session keys) | 0 |
4:4 | Part 4, clause 4: communications reference models, application and transport security profiles, compatibility and native modes, threats and attacks countered | 0 |
4:5 | Part 4, clause 5: specific requirements for the ICCP (IEC 60870-6) stack and for IEC 61850 | 0 |
4:6 | Part 4, clause 6: transport security (TLS application, cipher suites, session resumption and renegotiation, trust anchors, certificate size, revocation evaluation period, certifica | 0 |
4:8 | Part 4, clause 8: use of cryptographic algorithms (public-key, hash, signature, symmetric encryption, authenticated encryption, integrity check value) | 0 |
5:5.2 | Part 5, 5.2: threats addressed (spoofing, tampering, replay, eavesdropping) | 0 |
5:5.3 | Part 5, 5.3: design issues of the telecontrol environment | 0 |
5:5.4 | Part 5, 5.4: general principles (application layer only, generic definition mapped to protocols, bi-directional, key management, backwards tolerance, upgradeable, multiple connecti | 0 |
5:6.2 | Part 5, 6.2: theory of operation (association ID, authenticating, central authority, role-based access control, cryptographic keys, security statistics and events) | 0 |
5:7 | Part 5, clause 7: functional requirements (procedures, state machines, timers and counters, security statistics thresholds, reporting, event monitoring and logging) | 0 |
5:8.3 | Part 5, 8.3: station association procedure (public-key certificates, configuration of authorized remote stations, verification of certificates, update keys) | 0 |
5:8.4 | Part 5, 8.4: session key change procedure | 0 |
5:8.5 | Part 5, 8.5 and following: authentication of critical messages (challenge-response and aggressive mode), ASDU protection and error handling | 0 |
6:10 | Part 6, clause 10: extension of the LGOS and LSVS logical nodes | 0 |
6:11 | Part 6, clause 11: conformance (general, IEC 61850-8-1 profiles, VLAN profiles, SNTP profile) with PICS tables | 0 |
6:4 | Part 6, clause 4: operational issues, threats and attacks countered for IEC 61850 profiles | 0 |
6:5 | Part 6, clause 5: correlation of IEC 61850 and IEC 62351 parts (MMS security profiles, VLAN profiles, IEC 61850-8-2, OriginatorID binding) | 0 |
6:6 | Part 6, clause 6: multicast association protocols and replay protection for GOOSE and Sampled Values | 0 |
6:7 | Part 6, clause 7: security for SNTP | 0 |
6:8 | Part 6, clause 8: the extended PDU for GOOSE and SV (Ethertype, extension octets, calculated MAC domain, AES-GCM) | 0 |
6:9 | Part 6, clause 9: substation configuration language extensions (access point security capability, publish with security enabled, key policy and management, simulation) | 0 |
7:MON | Part 7 in use: monitoring of the information infrastructure with NSM objects | 0 |
7:NSM | Part 7: network and system management data objects for the power system information infrastructure | 0 |
8:10 | Part 8, clause 10: RBAC access token distribution models | 0 |
8:5 | Part 8, clause 5: the RBAC process model and concepts (subjects, roles, permissions, separation, criteria for defining roles) | 0 |
8:6 | Part 8, clause 6: pre-defined roles, role-to-permission assignment, custom roles, operational states and security events | 0 |
8:7 | Part 8, clause 7: simplified role assignment (generic roles across multiple role definitions) | 0 |
8:8 | Part 8, clause 8: definition of access tokens (mandatory and optional components, profiles A X.509 public-key certificate, B X.509 attribute certificate, C JSON Web Token, D RADIUS | 0 |
8:9 | Part 8, clause 9: verification of access tokens (multiple tokens, subject authentication, availability, validity period, integrity, issuer, role ID, revision, area of responsibilit | 0 |
90-3:5 | Part 90-3, clause 5: information collection, filtering and processing (IT and OT elements, SNMP agents, IDS and IPS probes, central NSM platforms, log collection, log agents, norma | 0 |
90-3:6 | Part 90-3, clause 6: information correlation and presentation (collection profiles for NSM and part 7, IEC 61850-specific monitoring, other SNMP objects, logs; events, incidents an | 0 |
90-3:7 | Part 90-3, clauses 7 and 8: monitoring use cases (substation, DER systems, large hydro, generation) and monitoring profiles for attack scenarios (malicious IED program change, unex | 0 |
9:4 | Part 9, clause 4: security concepts applicable to power systems (confidentiality, integrity, authentication, non-repudiation; cryptographic algorithms and concepts) | 0 |
9:5.2 | Part 9, 5.2 to 5.5: key management lifecycle, key usages, key management system security policy and design principles for power system operations | 0 |
9:5.6 | Part 9, 5.6: key agreement (Diffie-Hellman, key derivation functions, group key management) | 0 |
9:5.7 | Part 9, 5.7: public-key and privilege management infrastructures (registration and certification authorities, public-key certificates, attribute certificates, extensions) | 0 |
9:5.8 | Part 9, 5.8: certificate management (process, initial creation, onboarding, enrolment, CSR processing, enrolment protocols, trust anchor management) | 0 |
9:5.9 | Part 9, 5.9 to 5.11: revocation (CRL, OCSP, SCVP, recovery), trust via self-signed certificates, authorization and validation lists | 0 |
9:6 | Part 9, clause 6: normative key management requirements (security events, required cryptographic material, random number generation, object identifiers) | 0 |
9:7 | Part 9, clause 7: asymmetric key management (certificate components, generation and installation, key protection, certificate policy, trust anchor establishment and update, entity | 0 |
9:8 | Part 9, clause 8: symmetric key management (group keys for GOOSE, SV and PTP through GDOI; session keys for IEC 60870-5 and DNP3) | 0 |
OTHER-PARTS | Parts not held: 2 glossary, 12 DER resilience, 13 security topics for standards, 14 event logging, 90-1, 90-2, 100-1, 100-3, 100-4 | 0 |
PART-1 | IEC TS 62351-1:2007: introduction to security issues for the series | 0 |
PART-10 | IEC 62351-10 | 0 |
PART-100-6 | IEC 62351-100-6 | 0 |
PART-11 | IEC 62351-11 | 0 |
PART-3 | IEC 62351-3 | 0 |
PART-4 | IEC 62351-4 | 0 |
PART-5 | IEC 62351-5 | 0 |
PART-6 | IEC 62351-6 | 0 |
PART-7 | IEC 62351-7 | 0 |
PART-8 | IEC 62351-8 | 0 |
PART-9 | IEC 62351-9 | 0 |
PART-90-3 | IEC 62351-90-3 | 0 |
SERIES | IEC 62351: the series, its parts and what is held | 0 |