ICS Security
Last Updated:Sep 30, 2022
Activities
Since Stuxnet was discovered in 2010, IPA has been working on the launch of certification systems for industrial control systems (ICS) ,and support for critical ICS systems in order to improve security measures for critical ICS in Japan. Currently, we are continuing to work on the ICS security field, focusing on the following activities.
- Publication of risk assessment guide for ICS
- Support of risk assessment for domestic critical ICS systems
- Holding of risk assessment seminar for ICS(Japanese Only)
- Other Activities(Conducting trend and technical surveys regarding ICS security, Support of dissemination of security framework, Translation of useful overseas guideline, etc.)
Security Risk Assessment Guide for ICS (Industrial Control Systems)
In order to make risk assessment methods widely known to ICS owners in Japan, IPA has compiled our experience and know-how into the "Security Risk Assessment Guide for Industrial Control Systems". IPA has been conducting risk assessments for ICS and holding seminars using the guide.
- Security Risk Assessment Guide for Industrial Control Systems (Quick Guide)(2019.10)(PDF:4.0 MB)
- Risk Assessment for Industrial Control Systems in Japan (2020.04)(PDF:1.7 MB)
- Practical Examples of Security Risk Assessment for ICS ~Separate Volume of Security Risk Assessment Guide for ICS~ (2022.09)(PDF:5.7 MB)
- Asset-based Risk Assessment Sheet (2022.09)(Excel:211 KB)
- Business Impact-based Risk Assessment Sheet (2022.09)(ZIP:276 KB)
CPSF(Cyber Physical Security Framework )
Ministry of Economy, Trade and Industry (METI) published CPSF Ver. 1.0 in 2020 to make points of how to manage cyber physical security widely known to the domestic critical infrastructure industries. The framework refers to NIST CSF (Cyber Security Framework) and is targeting the realization of “Society 5.0”.
Related Links
-
CSSC Certification Laboratory(CSSC: ISO/IEC 62443-4 certification body)
-
JIPDEC(JIPDEC: ISO/IEC 62224-2(CSMS) certification body)
