80 likes | 356 Views
99.03.xx. 99.03.03. 99.03.01. 99.03.02. ISA 99 Technical Requirements. Situation assessment as seen by Dennis Holstein, Lead Editor. Situation today (Nov 2008). ISA 99 is a multipart standard to be aligned with IEC 62443 parts 99.01.01: Terminology, Concepts and Models: Published
E N D
99.03.xx • 99.03.03 • 99.03.01 • 99.03.02 ISA 99 Technical Requirements Situation assessment as seen by Dennis Holstein, Lead Editor ISA99WG04
Situation today (Nov 2008) • ISA 99 is a multipart standard to be aligned with IEC 62443 parts • 99.01.01: Terminology, Concepts and Models: Published • 99.02.01: Framework for a Security Program: In ballot • 99.02.02: Guideline for Operating a Security Program: Not started • 99.03.01: Target System Security Levels: Work-in-progress • 99.03.02: System Security Compliance Metrics: Work-in-progress • 99.03.03: Protection of Data at Rest: Work-in-progress • Derived requirements (99.03.0x) are prescriptive, requiring • Traceability to the 7 foundational requirements in 99.01.01 • Supporting rationale with use cases • Security assurance metrics • Technical Requirements work-in-progress task teams • Foundational requirements • Zones, conduits and security levels • Derived requirements ISA99WG04
Maturity assessment ISA99WG04
In summary • Accelerate publication of technical requirements • ISA-DS99.03.01 “Target Security Levels” • With editorial changes, is it ready to ballot? • Use formal review processes and procedures of ISA and IEC in parallel • Use agreed-to ISA/IEC document template • Ballot resolution team address comments received from both balloting bodies • Charlie Robinson will coordinate ISA & IEC (via Tom Phinney) balloting • Lessons learned feed-forward to next publication in the series ISA99WG04