GBZ43030-2023 English PDFUS$779.00 ยท In stock
Delivery: <= 6 days. True-PDF full-copy in English will be manually translated and delivered via email. GBZ43030-2023: Low-voltage switchgear and controlgear - Security aspects Status: Valid
Basic dataStandard ID: GB/Z 43030-2023 (GB/Z43030-2023)Description (Translated English): Low-voltage switchgear and controlgear - Security aspects Sector / Industry: National Standard Classification of Chinese Standard: K31 Classification of International Standard: 29.130.20 Word Count Estimation: 39,368 Date of Issue: 2023-09-07 Date of Implementation: 2024-04-01 Issuing agency(ies): State Administration for Market Regulation, China National Standardization Administration GBZ43030-2023: Low-voltage switchgear and controlgear - Security aspects---This is a DRAFT version for illustration, not a final translation. Full copy of true-PDF in English version (including equations, symbols, images, flow-chart, tables, and figures etc.) will be manually/carefully translated upon your order.GB /Z 43030-2023.Low-voltage switchgear and control equipment network security ICS 29.130.20 CCSK31 National Standardization Guiding Technical Documents of the People's Republic of China Low voltage switchgear and control equipment cyber security (IEC TS63208.2020,IDT) Published on 2023-09-07 2024-04-01 Implementation State Administration for Market Regulation Released by the National Standardization Administration Committee Table of contentsPreface III Introduction IV 1 Scope 1 2 Normative reference documents 1 3 Terms, definitions and abbreviations2 3.1 Terms and Definitions 2 3.2 Abbreviations 4 4 General requirements 5 5 Security Goals 5 6 Security life cycle management 6 6.1 General requirements 6 6.2 Security risk assessment7 6.3 Security risk response 7 6.4 Safety requirements specifications 8 6.5 Important data 8 6.6 System Architecture 8 7 Safety requirements 11 7.1 General requirements11 7.2 Network security elements 12 7.3 Physical access and environment12 7.4 Equipment requirements13 8 Installation, Operation and Maintenance Instructions15 9 Development and Testing15 9.1 General development methods 15 9.2 Test 16 Appendix A (Informative) Cybersecurity and Electrical System Architecture 17 A.1 General requirements 17 A.2 Typical architecture involving complete switchgear and controlgear17 A.3 Safety levels and product standards18 Appendix B (Informative) Use Case Study 19 B.1 General requirements 19 B.2 Use case 1---Prevent malicious circuit breaker firmware upgrades19 B.3 Use Case 2---Preventing unauthorized access to the power production network 20 B.4 Use Case 3 --- Preventing DDoS (Distributed Denial of Service) attacks via insecure IoT devices 21 B.5 Use Case 4 --- Preventing the use of illegal devices to gain unauthorized access to electrical networks 22 B.6 Use Case 5---Prevent malicious firmware upgrades of sensors installed in machines wired via the IO-Link interface (e.g. proximity switch) 23 B.7 Use Case 6 ---HMI. Human Machine Interface - Protection against unauthorized access to simple sensors (installed in the machine) - Incorrect parameterization 24 B.8 Use Case 7 --- HMI. Human Machine Interface - Preventing unauthorized access to complex sensors (installed in the machine) - Incorrect parameterization 25 B.9 Use case 8---Prevent illegal access to sensors installed in the machine (such as proximity switches) through the wireless communication interface (WCI) Appendix C (informative) Basic network security elements 27 C.1 General requirements 27 C.2 Identification and authentication27 C.3 Usage Control 27 C.4 System integrity27 C.5 Data confidentiality27 C.6 Restricted data flow27 C.7 Timely response to incidents28 C.8 Resource Availability28 Appendix D (Informative) Switchgear and Control Equipment User Guide 29 D.1 General requirements 29 D.2 Risk assessment and security plan 29 D.3 Guidelines for the design and installation of integrated switchgear and controlgear systems29 Reference 32ForewordThis document complies with the provisions of GB/T 1.1-2020 "Standardization Work Guidelines Part 1.Structure and Drafting Rules of Standardization Documents" Drafting. This document is equivalent to IEC TS63208.2020 "Cybersecurity of low-voltage switchgear and control equipment". The file type is produced by IEC 's technical The technical specifications were adjusted into my country's guiding technical documents. This document has made the following minimal editorial changes. ---Supplement the Chinese name of "IPsec" mentioned in the text and add it to the abbreviations section (see 3.2 and 7.4.7). Please note that some content in this document may be subject to patents. The publisher of this document assumes no responsibility for identifying patents. This document is proposed by the China Electrical Equipment Industry Association. This document is under the jurisdiction of the National Low Voltage Electrical Equipment Standardization Technical Committee (SAC/TC189). This document was drafted by. Shanghai Electrical Apparatus Research Institute, Shanghai Chint Intelligent Technology Co., Ltd., Schneider Electric (China) Co., Ltd. Shanghai Branch, Xiamen Hongfa Switchgear Co., Ltd., Qingdao Dingxin Communications Co., Ltd., Siemens (China) Co., Ltd., Delixi Electric Co., Ltd., Hangzhou Electric Power Equipment Manufacturing Co., Ltd. Yuhang Qunli Complete Electrical Manufacturing Branch, Zhejiang Tianzheng Electric Co., Ltd. Company, Jiangsu Miter Internet of Things Technology Co., Ltd., Shanghai Hongtan Intelligent Technology Co., Ltd., Sao Tome Electric Co., Ltd., Omron Automation (China (China) Co., Ltd., Foshan Jiahua Electric Technology Co., Ltd., Hongguang Intelligent Technology Co., Ltd., Shanghai Electrical Apparatus Research Institute (Group) Ltd. The main drafters of this document. Huang Jingye, Wang Yuxuan, Wang Limin, Wang Ping, Zhang Xieli, Wang Jianhua, Li Hui, Gao Longlong, Guo Qiang, Gao Ping, Shi Mengyun, Zhao Jie, Zhao Hongliang, Yang Jingcong, Wu Weiqing, Chen Weiwei, Xue Ji.IntroductionAn increasing number of low-voltage switchgear and control equipment (referred to as "devices" in this document) are equipped with data communications capabilities, which automatically increases the number of network Cybersecurity risks. In addition, information technology is increasingly interconnected with industrial systems and is even integrated into industrial systems, thus increasing the number of One risk. Typically, low-voltage switching equipment (such as circuit breakers) or control equipment (such as overload relays or proximity switches) are equipped with data communication interfaces. it They have local and remote connection capabilities and can be connected to logic controllers or remote display terminals to access actual electrical parameters, monitoring data, etc. data, record data and remote upgrade data. For these typical power distribution and machinery control equipment, whether or not they have data communication capabilities, in order to keep the equipment protection functions safe and complete To achieve an acceptable level of integrity, minimum network security requirements need to be specified. These requirements are intended to limit the vulnerabilities of data communications interfaces. In order to maintain freedom of innovation to the greatest extent possible, the relevant requirements for a specific application are best determined through a systematic risk assessment approach. This document is intended to. a) Establish awareness of cybersecurity risks related to unexpected operations and loss of protective functions; b) Provide minimum cybersecurity requirements for equipment to reduce unintended operation and protection functions in power distribution devices and machinery control systems possibility of loss; c) Provide guidance to avoid impairment of equipment functionality due to the implementation of safety countermeasures in all operating modes. This document gives countermeasures applicable to the design of equipment (hardware, firmware, network interfaces, access control, systems) and the requirements for implementation and use. Guidance for considering alternative countermeasures. This document refers to ISO /IEC 27001, IEC 62443 (all parts) and IEC 62351 (all parts) related content. As a first stage, the contents of this document will provide a reference for product standards. Future generalization of low-voltage switchgear and control equipment Safety requirements are expected to be specified in IEC 60947-1. Low voltage switchgear and control equipment cyber security1 ScopeThis document applies to the main safety-related functions of switchgear and control equipment throughout their life cycle. suitable for use in its environmental conditions Limit the scope of wired and wireless data communications methods and the physical accessibility of the device. This document aims to increase awareness of security aspects and provide guidance and requirements for reasonable countermeasures to reduce risk vulnerabilities. This document focuses on potential risks resulting from vulnerabilities. ---Unexpected operation of switchgear, control equipment or sensors may lead to hazardous situations; ---Protection function failure (over current, leakage current to ground, etc.). This document does not include security requirements for information technology (IT) and industrial automation and control systems (IACS). For guidance only when switching equipment use appropriate security countermeasures in equipment and control equipment derived from the basic safety publications ISO /IEC 27001 and Shared safety publication IEC 62443 (all parts). As a product safety publication, this document follows IEC Guide 120 and includes typical use case studies given in Appendix B.2 Normative reference documentsThe contents of the following documents constitute essential provisions of this document through normative references in the text. Among them, the dated quotations For undated referenced documents, only the version corresponding to that date applies to this document; for undated referenced documents, the latest version (including all amendments) applies to this document. GB/T 22080-2016 Information technology security technology information security management system requirements (ISO /IEC 27001.2013, IDT) GB /Z 41912-2022 Low-voltage switchgear and control equipment embedded software development guide (IEC TR63201.2019, IDT) GB/T 42456-2023 Security technical requirements for information security IACS components of industrial automation and control systems (IEC 62443- 4-2.2019,IDT) GB/T 42457-2023 Industrial automation and control system information security product security development life cycle requirements (IEC 62443- 4-1.2018,IDT) IEC 60364-7-729 Low-voltage electrical installations Part 7-729.Requirements for operation and maintenance of aisles for special installations or locations trolgear-Part 1.Generalrules) Note. GB/T 14048.1-2012 Low-voltage switchgear and control equipment Part 1.General provisions (IEC 60947-1.2011, MOD) ......Tips & Frequently Asked Questions:Question 1: How long will the true-PDF of GBZ43030-2023_English be delivered?Answer: Upon your order, we will start to translate GBZ43030-2023_English as soon as possible, and keep you informed of the progress. The lead time is typically 4 ~ 6 working days. The lengthier the document the longer the lead time.Question 2: Can I share the purchased PDF of GBZ43030-2023_English with my colleagues?Answer: Yes. The purchased PDF of GBZ43030-2023_English will be deemed to be sold to your employer/organization who actually pays for it, including your colleagues and your employer's intranet.Question 3: Does the price include tax/VAT?Answer: Yes. Our tax invoice, downloaded/delivered in 9 seconds, includes all tax/VAT and complies with 100+ countries' tax regulations (tax exempted in 100+ countries) -- See Avoidance of Double Taxation Agreements (DTAs): List of DTAs signed between Singapore and 100+ countriesQuestion 4: Do you accept my currency other than USD?Answer: Yes. If you need your currency to be printed on the invoice, please write an email to Sales@ChineseStandard.net. In 2 working-hours, we will create a special link for you to pay in any currencies. Otherwise, follow the normal steps: Add to Cart -- Checkout -- Select your currency to pay. |