Cybersecurity

Cybersecurity, in a functional safety context, means protecting the safety instrumented system (SIS) from deliberate interference — someone reaching the logic solver, the engineering workstation, or the network in between and changing what the system does. It matters here for one specific reason: risk studies credit protection layers as independent, and an intruder with the right access can take out several at once. That is common cause failure with a person behind it. IEC 61511 points the detailed work at the IEC 62443 series and ISA-TR84.00.09.

Key Points

  • The threat surface is the whole path to the SIS: engineering workstations, remote-access links, portable media, vendor connections, and any network shared with the basic process control system (BPCS).
  • Segregation is the workhorse control — keeping the SIS off the same network as the BPCS so one compromise cannot reach both.
  • Security controls belong in the safety requirements specification and get re-checked at every management of change, not bolted on after commissioning.

Example

An engineer plugs a laptop into the safety PLC programming port to pull a diagnostic log. The port has no key switch and no password, so that same connection could have written new application program logic instead. Nothing malicious happened, but the plant has just demonstrated that its SIS can be rewritten by anyone who reaches the panel — exactly the finding a security risk assessment (SRA) exists to surface.

Go deeper: Hazard and Risk Assessment (H&RA): The Foundation of Functional Safety

See Also: SRA, BPCS, safety PLC

Cited Sources

  • ISA/IEC 62443 series, Security for Industrial Automation and Control Systems
  • ISA-TR84.00.09, Cybersecurity Related to the Safety Life-cycle