Manufacturing Engineering Laboratory National Institute of Standards and Technology
ISD Research Areas
ISD home About ISD ISD Research Areas ISD's Products and Services What's New in ISD Search ISD

 

Home

Join the PCSRF

What's New

Upcoming Meetings

Meeting Minutes and Reports

Documents

Participants

Mailing List Information

Resources and Links

Testbed

 

 


Process Control Security Requirements Forum (PCSRF)

Documents

SCADA Protection Profiles

In March 2005, a PCSRF working group was created to take the next step after finishing the SPP-ICS and develop a SCADA PP. A two Protection Profile approach is being taken to develop the SCADA PP. A Control Center PP will specify the requirements for the SCADA Control Center and a Field Device PP will be developed to address the requirements for the field communications and devices. The two PPs will then be connected using the methodology defined in the Common Criteria.

A collaboration site is available to view the draft documents, comments, threaded messages, milestones and applicable background documents. For a site account please contact peterson@digitalbond.com

Draft Field Device PP

Draft SCADA Field Device PP Security Objectives 03-Jan-2006: (PDF) / (MSWord)

Draft SCADA Field Device PP Security Environment 30-Nov-2005: (PDF) / (MSWord)

Draft SCADA Field Device PP Target of Evaluation (TOE) 17-Oct-2005: (PDF) / (MSWord)

System Protection Profile for Industrial Control Systems (SPP-ICS)

The PCSRF SPP-ICS is designed to present a cohesive, cross-industry set of security requirements for new industrial control systems. The security requirements specified in the SPP-ICS have been captured during face-to-face meetings and conference calls of the PCSRF group and specific industry sectors groups. The SPP-ICS is designed to be an industry voice to the industrial control system vendors and system integrators, defining the security capabilities that are desired in new products and systems. It is a consensus-based specification, not a NIST specification. In addition to the final version of the SPP-ICS, intermediate documents created in its development are listed below.

System Protection Profile for Industrial Control Systems (SPP-ICS) Version 1.0 (PDF)

Security Capabilities Profile for Industrial Control Systems Document (PDF)

Process Control System Component Security Profile Specification (SPS) Document (PDF)

IEC 61508 Safety Standard Review (PDF)

Fault Tree Analysis Document (PDF)

Security Requirements and Objectives Draft (PDF)

Chemical Sector - Security Objectives (PDF)

Categorization of Vulnerabilities - Discrete Manufacturing Security Meeting (PDF)

Discrete Manufacturing Requirements (PDF)

Generic Composite Industrial Control System Network Architecture - DCS (PDF)

Generic Composite Industrial Control System Network Architecture - SCADA (PDF)

Support Contract Statement of Work (SOW) (PDF)

Papers and Presentations

A listing of recent NIST PCSRF papers and presentations. Also listed are some industry presentations from PCSRF face-to-face meetings during the development of the SPP-ICS.

NIST Industrial Control System Security Activities, ISA, October, 2005 (Paper / Presentation)

IT Security for Industrial Control Systems: Requirements Specification and Performance Testing

Rockwell presentation on NCMS meeting agenda

Decisive Analytics Common Criteria Primer Presentation

Honeywell Threats Presentation

isd-webmaster@cme.nist.gov
Date Created: January 19, 2006
Last updated: January 24, 2006