ISASecure ACSSA - 2024-5-8
ISASecure ACSSA - 2024-5-8
ISASecure ACSSA - 2024-5-8
May 2024
Mission Vision
Publish a consensus The assessment specification
specification and establish a and resulting standard report
global scheme for assessing will become the de-facto
and certifying the foundational document of
cybersecurity of automation reference for assessing and
and control systems in use at certifying OT cybersecurity,
asset owner sites based on globally, by asset owners,
the Asset Owner series of consultants, certification
ISA/IEC 62443 standards. bodies and public policy
makers….much like the GAAP
standards developed by FASB
for financial accounting.
Who will use the ACSSA Assessment Specification?
Supporter
Generac(supporter)
Interstates (supporter)
Armexa (supporter)
Securing Things (supporter)
CyberPrism (supporter)
IACS Consulting (supporter)
Use-cases for
ACSSA
Assess cybersecurity of production assets and
control systems at asset owner site:
in steady-state
recently upgraded (Brownfield)
site commissioning stage (Greenfield)
Phase One – Develop Core ACSSA Scheme from ISA/IEC 62443
ISA/IEC 62443 Asset “Core” ISASecure ACSSA Program
Owner Standards
(345 requirements)
Assessment Certification
62443-2-1 – Security
program requirements Assessment Specification Certification Definition
Standardized assessment methods, Pass/fail
tools, assessor guidance Program policies and procedures
ISASecure TSC
62443-3-2 – Risk assessment
Develops
and system design Assessor Company
Specifications Three-day Training Class
Accreditation
Asset owner standards, ACSSA
ISO 17020 and scheme specific
assessment methodology
62443-3-3 – System requitements
requirements and security
levels Assessor Personnel
Specification Licensing
Credential Program
Agreements
Profile, education, experience,
62443-2-4 – Service provider End-users, consultants, CB, other
certifications
Requirements
Phase II “Core” ISASecure ACSSA
Certification Specification used to create sector
assessment profiles
• Security Requirements
• Detailed assessor guidance
• Use of tools and methods
• Certification definition
• Policies and procedures
• Pass / Fail metrics
Other
Railways
Sectors
Building Electric
Pipelines Ports
Controls Sector
Water /
Wastewater
ACSSA Project Organization
ISASecure Program
Manager
Carol Muehrcke