{"id":618,"date":"2023-04-01T09:34:00","date_gmt":"2023-04-01T07:34:00","guid":{"rendered":"https:\/\/pilz-magazine.com\/de\/?p=618"},"modified":"2024-09-11T10:42:43","modified_gmt":"2024-09-11T08:42:43","slug":"spotlight-on-security","status":"publish","type":"post","link":"https:\/\/pilz-magazine.com\/en\/spotlight-on-security\/","title":{"rendered":"Spotlight on Security!"},"content":{"rendered":"\n<p>The plant has a CE marking. The safety com\u00adpo\u00adnents installed in it meet the require\u00adments for the required Per\u00adfor\u00admance Level (PLr) in accor\u00addance with EN&nbsp;ISO&nbsp;13849\u20131 or the required Safety Integrity Level (SIL) in accor\u00addance with EN&nbsp;IEC&nbsp;62061. The plant can be designed to be func\u00adtion\u00adally safe. The good feeling asso\u00adci\u00adated with this begins to waver, how\u00adever. Because machinery is being equipped with increas\u00adingly more dig\u00adital ele\u00adments that make new demands of Secu\u00adrity: Could some\u00adbody from out\u00adside damage my soft\u00adware? Could some\u00adbody without autho\u00adri\u00adsa\u00adtion gain access to the machine and make changes to the pro\u00adgram\u00adming?<\/p>\n\n\n\n<p>The stan\u00addards organ\u00adi\u00adsa\u00adtions ISO and IEC have responded and are aiming to resolve these and sim\u00adilar con\u00adcerns: they are upgrading and cur\u00adrently defining new require\u00adments for prod\u00aducts, plant and machinery with updated stan\u00addards that are intended to shift the focus to Indus\u00adtrial Secu\u00adrity. The new Machinery Reg\u00adu\u00adla\u00adtion that will be replacing the Machinery Direc\u00adtive is also con\u00adcerned with this. But that\u2019s not all: with the first draft of the Cyber Resilience Act, an EU reg\u00adu\u00adla\u00adtion is being pre\u00adpared that lays down its own require\u00adments for cyber\u00adse\u00adcu\u00adrity for all com\u00adpo\u00adnent and machine man\u00adu\u00adfac\u00adturers and oper\u00ada\u00adtors of plant and machinery. But one thing at a time \u2026<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">EN\u202fIEC\u202f62061 \u2013 Security as a safety issue<\/h2>\n\n\n\n<p>In addi\u00adtion to EN&nbsp;ISO&nbsp;13849, EN&nbsp;IEC&nbsp;62061 is the most impor\u00adtant stan\u00addard for func\u00adtional safety. The stan\u00addard defines the require\u00adments and includes rec\u00adom\u00admen\u00adda\u00adtions for the design, inte\u00adgra\u00adtion and val\u00adi\u00adda\u00adtion of safety-related con\u00adtrol sys\u00adtems (SCS) for machinery. Pub\u00adlished in 2022 as an updated ver\u00adsion, it also defines Secu\u00adrity as a safety issue: the stan\u00addard spec\u00adi\u00adfies that both \u201cinten\u00adtional attacks on the hard\u00adware, appli\u00adca\u00adtion pro\u00adgrams and related soft\u00adware, as well as unin\u00adtended events resulting from human error\u201d are to be taken into account in the safety life\u00adcycle and during the entire life\u00adcycle of the plant and machinery. These must not adversely affect the integrity of the Safety.<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"640\" src=\"https:\/\/pilz-magazine.com\/en\/wp-content\/uploads\/sites\/24\/2023\/08\/Pilz-Industrial-Security_amendment-standards-EN-1024x640.jpg\" alt class=\"wp-image-1862\" srcset=\"https:\/\/pilz-magazine.com\/en\/wp-content\/uploads\/sites\/24\/2023\/08\/Pilz-Industrial-Security_amendment-standards-EN-1024x640.jpg 1024w, https:\/\/pilz-magazine.com\/en\/wp-content\/uploads\/sites\/24\/2023\/08\/Pilz-Industrial-Security_amendment-standards-EN-300x188.jpg 300w, https:\/\/pilz-magazine.com\/en\/wp-content\/uploads\/sites\/24\/2023\/08\/Pilz-Industrial-Security_amendment-standards-EN-768x480.jpg 768w, https:\/\/pilz-magazine.com\/en\/wp-content\/uploads\/sites\/24\/2023\/08\/Pilz-Industrial-Security_amendment-standards-EN-1536x960.jpg 1536w, https:\/\/pilz-magazine.com\/en\/wp-content\/uploads\/sites\/24\/2023\/08\/Pilz-Industrial-Security_amendment-standards-EN-540x338.jpg 540w, https:\/\/pilz-magazine.com\/en\/wp-content\/uploads\/sites\/24\/2023\/08\/Pilz-Industrial-Security_amendment-standards-EN-1080x675.jpg 1080w, https:\/\/pilz-magazine.com\/en\/wp-content\/uploads\/sites\/24\/2023\/08\/Pilz-Industrial-Security_amendment-standards-EN.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">Stan\u00addards specify: the focus is shifting to Secu\u00adrity.<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">ISO&nbsp;13849\u20131 \u2013 safety-related software<\/h2>\n\n\n\n<p>There is a final draft avail\u00adable of the revised ver\u00adsion of ISO&nbsp;13849\u20131. It is expected to be pub\u00adlished in the first half of the year (for more details, see page&nbsp;4). One impor\u00adtant aspect relates to the require\u00adments with regard to soft\u00adware and man\u00adage\u00adment of func\u00adtional safety \u2013 such as how data within machinery soft\u00adware are pro\u00adtected. Var\u00adious soft\u00adware types are cov\u00adered, such as safety-\u00adre\u00adlated embedded soft\u00adware (SRESW), safety-\u00adre\u00adlated appli\u00adca\u00adtion soft\u00adware (SRASW) or soft\u00adware for para\u00admeter set\u00adting. The stan\u00addard con\u00adtains sug\u00adges\u00adtions for improve\u00adment with regard to how these can be linked to the require\u00adments for pro\u00adgram\u00adming lan\u00adguages with lim\u00adited (\u201clim\u00adited vari\u00adability lan\u00adguage\u201d, LVL) or unlim\u00adited lan\u00adguage scope (\u201cfull vari\u00adability lan\u00adguage\u201d, FVL). It is far from clear when it will be har\u00admonised into the EU stan\u00addard EN&nbsp;ISO&nbsp;13849\u20131 or when to expect an answer to the ques\u00adtion of whether there will be a tran\u00adsi\u00adtion period after pub\u00adli\u00adca\u00adtion of the stan\u00addard in the Offi\u00adcial Journal and, if so, how long this will be.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The new Machinery Regulation \u2013 final draft<\/h2>\n\n\n\n<p>The Euro\u00adpean Par\u00adlia\u00adment and the Council of the Euro\u00adpean Union have agreed on a final ver\u00adsion of the new Machinery Reg\u00adu\u00adla\u00adtion. It will be pub\u00adlished soon. Once the reg\u00adu\u00adla\u00adtion is pub\u00adlished, the stan\u00addards com\u00admit\u00adtees have 42 months to adapt the applic\u00adable stan\u00addards to the new spec\u00adi\u00adfi\u00adca\u00adtions. Meaning also cre\u00adating har\u00admonised stan\u00addards that make it easier for us to achieve com\u00adpli\u00adance with the reg\u00adu\u00adla\u00adtion. \u201cThis is a lot of work,\u201d explains Klaus D\u00fcrr, Vice Pres\u00adi\u00addent Stan\u00addards Group at Pilz. \u201cThis also includes the \u2018Pro\u00adtec\u00adtion against cor\u00adrup\u00adtion\u2019 sec\u00adtion in which the Machinery Reg\u00adu\u00adla\u00adtion defines require\u00adments for cyber\u00adse\u00adcu\u00adrity and sets spec\u00adi\u00adfi\u00adca\u00adtions for the life phases of a machine. The safety func\u00adtions must not be affected by this.\u201d A sample extract from the draft: \u201cThe machinery [\u2026] shall be designed and con\u00adstructed so that the con\u00adnec\u00adtion to it of another device, via any fea\u00adture of the con\u00adnected device itself or via any remote device that com\u00admu\u00adni\u00adcates with the machinery [\u2026] does not lead to a haz\u00adardous sit\u00adu\u00ada\u00adtion.\u201d<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Cyber Resilience Act \u2013 an independent EU regulation<\/h2>\n\n\n\n<p>The first draft of the Cyber Resilience Act is directed, among others, toward man\u00adu\u00adfac\u00adturers of prod\u00aducts and machinery with dig\u00adital ele\u00adments, be it soft\u00adware or hard\u00adware, as well as oper\u00ada\u00adtors. In addi\u00adtion to com\u00adpre\u00adhen\u00adsive spec\u00adi\u00adfi\u00adca\u00adtions on the topic of Indus\u00adtrial Secu\u00adrity, the legal pro\u00advi\u00adsion requires that product fea\u00adtures as well as the plant or machinery have a suit\u00adable cyber\u00adse\u00adcu\u00adrity level which must be ver\u00adi\u00adfied based on a risk assess\u00adment. The EU reg\u00adu\u00adla\u00adtion is expected to be pub\u00adlished in two to three years.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The main question: \u201cHow?\u201d<\/h2>\n\n\n\n<p>The ques\u00adtion of how all these upcoming nor\u00adma\u00adtive require\u00adments for Secu\u00adrity can be imple\u00admented well and effi\u00adciently by inter\u00adna\u00adtional industry remains open. The chal\u00adlenges of taking the new require\u00adments into con\u00adsid\u00ader\u00ada\u00adtion in existing and new devel\u00adop\u00adment and man\u00adu\u00adfac\u00adturing processes are under\u00adstand\u00adably enor\u00admous. \u201cWe rec\u00adom\u00admend early action,\u201d states Arndt Christ, Vice Pres\u00adi\u00addent Cus\u00adtomer Sup\u00adport Inter\u00adna\u00adtional at Pilz. \u201cWe are staying on the ball around the world for our cus\u00adtomers. My staff are answering ques\u00adtions around the clock \u2013 about our product port\u00adfolio but also gen\u00aderal ques\u00adtions about how plant and machinery can be devel\u00adoped and oper\u00adated securely. Or how Secu\u00adrity require\u00adments are even to be iden\u00adti\u00adfied.\u201d In response Pilz is cur\u00adrently also expanding its range of ser\u00advices.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Along\u00adside machinery safety, the stan\u00addards land\u00adscape is focusing increas\u00adingly on Indus\u00adtrial Secu\u00adrity. Because with digi\u00adti\u00adsa\u00adtion and net\u00adworking the envi\u00adron\u00adment is \u00adcur\u00adrently under\u00adgoing change. We are high\u00adlighting what the most impor\u00adtant changes to stan\u00addards in 2023 mean for machine man\u00adu\u00adfac\u00adturers and oper\u00ada\u00adtors. <\/p>\n","protected":false},"author":29,"featured_media":620,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"wp_typography_post_enhancements_disabled":false,"footnotes":""},"categories":[19,4,27,1],"tags":[],"class_list":["post-618","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industrial-security","category-issue-1-2023","category-laws-and-standards","category-pilz-magazine"],"acf":[],"_links":{"self":[{"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/posts\/618","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/comments?post=618"}],"version-history":[{"count":4,"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/posts\/618\/revisions"}],"predecessor-version":[{"id":1863,"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/posts\/618\/revisions\/1863"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/media\/620"}],"wp:attachment":[{"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/media?parent=618"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/categories?post=618"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/tags?post=618"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}