-

Security-relevant Laws and Industrial Standards

It is important to understand that IT security is not only a new "product feature" that a vendor can implement more or less well at its own discretion. Instead, the integration of security features into automation equipment, systems and components is now required by national and international laws.

Therefore, this topic gives a simplified overview on the most essential security-related laws, standards and regulations. In general, a distinction must be made between legal requirements, recommendations and standards that define the necessary steps for the implementation of security-related measures and procedures.

Dieses Thema enthält die folgenden Abschnitte:

Security Laws - What must be done...

IT Security Act (V2.0 valid from May 28, 2021)

NIS Directive

European Cybersecurity Act (3/2019)

Basic Security Standards - How to implement secure processes

Standards describe how precisely measures and procedures can be implemented to meet legal requirements. The basic standards in the context of industrial automation systems are the ISO 2700x series and the IEC 62443.

Weitere Infos
For details on IT and ICS (OT) please refer to the topic "IT and OT/ICS: A Comparison".

Sector-specific Security Standards

Based on national legislation, various specific security standards have been developed by industry associations especially for the requirements in their respective industries. The table below shows some examples. However, the international standard IEC 62443 is the only one with a cross-industry approach, addressing all participants in the value chain and also enabling certification procedures.

StandardTarget groupMain purposeGeographical/
industry focus
BDEW White PaperDevice/component manufacturers,
system integrators
Security requirements for suppliersD, A, CH
Energy & water sectors
WIB Security StandardDevice/component manufacturers,
system integrators
Device/component manufacturer certificationOil & gas sector
ISO/IEC 27019Asset owners,
plant operators
IT security for control systemsEnergy sector
NIST 800-82Asset owners,
plant operators
Technical security recommendationsUSA
NERC CIPAsset owners,
plant operators
Increasing reliability of energy supply infrastructureUSA, Canada
IEC 62443Device/component manufacturers,
system integrators,
plant operators
Requirements for secure products, secure solutions, and secure operationGeneral industry sector

Further links

Further information is available on the following websites (partly in German):