verticale

Cybersecurity Industriale: ISA99 / IEC62443 - Introduzione alla norma e alla sua applicazione: casi di studio

Come proteggiamo i Sistemi di controllo, telecontrollo e automazione nell’industria e nelle infrastrutture con ISA99/IEC62443.

Scarica il PDF Scarica il PDF
Aggiungi ai preferiti Aggiungi ai preferiti


Atti di convegni o presentazioni contenenti case history
SAVE Milano aprile 2016 Le normative come fattore di competitività

Pubblicato
da Alessia De Giosa
SAVE Milano 2016Segui aziendaSegui




Settori: 

Parole chiave: 


Estratto del testo
Milano Milano, 14 aprile 2016 Come proteggiamo i Sistemi di
controllo, telecontrollo e automazione
nell''industria e nelle infrastrutture con
ISA99/IEC62443'
Enzo M. Tieghi
etieghi@servitecno.it
'ad esempio' (chi non conosce Suki') 2 Identifichiamo e definiamo il perimetro
IT Security & Control System Protection: dove'
4 ANSI/ISA95 Functional Hierarchy www.isa.org Level 4 Level 1 Level 2 Level 3 Business Planning & Logistics Plant Production Scheduling, Operational Management, etc Manufacturing Operations Management Dispatching Production, Detailed Production Scheduling, Reliability Assurance, ... Batch Control Discrete Control Continuous Control 1 - Sensing the production process, manipulating the production process 2 - Monitoring, supervisory control and automated control of the production process 3 - Work flow / recipe control to produce the desired end products. Maintaining records
and optimizing the production process. Time Frame Days, Shifts, hours, minutes, seconds 4 - Establishing the basic plant schedule - production, material use, delivery, and
shipping. Determining inventory levels. Time Frame Months, weeks, days Level 0 0 - The actual production process Level 4 Level 1 Level 2 Level 3 Business Planning & Logistics Plant Production Scheduling, Operational Management, etc Manufacturing Operations Management Dispatching Production, Detailed Production Scheduling, Reliability Assurance, ... Batch Control Discrete Control Continuous Control 1 - Sensing the production process, manipulating the production process 2 - Monitoring, supervisory control and automated control of the production proces 3 - Work flow / recipe control to produce the desired end products. Maintaining records
and optimizing the production process. Time Frame Days, Shifts, hours, minutes, seconds 4 - Establishing the basic plant schedule - production, material use, delivery, and
shipping. Determining inventory levels. Time Frame Months, weeks, days Level 0 0 - The actual production process No alle ''reti piatte': Seg/Seg Segmentare & Segregare Segmentazione e segregazione di reti di impianto in Zones & Conduits (secondo ISA99/IEC62443) Data Server File/Print Server App. Server Workstation Laptop computer Router Plant A Zone Controller Controller I/O I/O App. Server Data Server Maint. Server Plant A Control Zone Firewall Data Server File/Print Server App. Server Workstation Laptop computer Router Plant B Zone Data Server File/Print Server App. Server Workstation Laptop computer Router Plant C Zone Mainframe Workstation Laptop computer Server Server Enterprise Zone Firewall Enterprise Conduit Plant Control Conduit Controller Controller I/O I/O App. Server Data Server Maint. Server Plant B Control Zone Firewall Firewall Plant Control Conduit Controller Controller I/O I/O App. Server Data Server Maint. Server Plant C Control Zone Firewall Firewall Plant Control Conduit Esempio di ''Security Architecture' nei sistemi di automazione e control o Enterprise Control Network Manufacturing Operations Network Perimeter Control Network Control System Network Process Control Network Protezione di Zone & Conduits con Firewal s
(multilayered defence)
Corporate Firewall Industrial Firewall Source: Byres - Tofino Esempio di rete ''con protezioni' esempio: in stabilimento con connessione remota (processo continuo) 1
0 Esempio di rete stabilimento (produzione batch) 1
1 Reti Cablate e Reti Wireless Il wireless arriva in fabbrica Smart Control Systems Smart Analytical Smart Final Control Smart Asset Optimization Smart Safety Smart Measurement Smart Machinery Health Smart Wireless 13 SCADA
Server
Client Scada-Historian-KPI 1 3 4 6 7 Mobile BI- KPI/
Allarmi
RTU su APN Privata/Pubblica 2 5 Datacenter/Historian
Server
KPI/
ALM
Server
CLOUD, MOBILE, BYOD'. Enzo Maria Tieghi n Amministratore Delegato di ServiTecno
(da oltre 30 anni software industriale) n Socio ANIPLA, ISA, ISPE, AIIC, attivo in associazioni e
gruppi di studio per la cyber security industriale (ISA s99
member) n In Advisory Board, gruppi e progetti internazionali su
Industrial Security e CIP (Critical Infrastructure Protection) n Co-autore ed autore pubblicazioni, articoli e memorie 16 Dubbi' Domande' Enzo M. Tieghi etieghi@servitecno.it


In evidenza

ExxonMobil
Grassi Mobil™ - Formulati per fornire elevate prestazioni anche in condizioni operative estreme
SD Project
SPAC : Il Software per la progettazione Elettrica
© Eiom - All rights Reserved     P.IVA 00850640186