SPE 5 keeps IACS information from being disclosed or altered improperly — through
classification, confidentiality and integrity controls, retention rules, cryptography and
careful handling of safety-system configuration modes.
DATA 1 – Protection of data
Reference: ISA/IEC 62443-2-1, Clause 10.2
DATA 1.1: Data classification
Clause: 10.2.1
Summary
IACS data that needs protection shall be identified and classified according to how strongly
it must be safeguarded.
Practice examples: Classify and control sharing of network diagrams, PLC and
switch configurations, vulnerability assessment reports, zone and conduit drawings, recipes
and process programs — disclosure or unauthorised change of these artefacts can enable
targeted attacks. Define classification levels for access, copying, transmission and disposal,
and maintain a document lifecycle process for IACS information.
DATA 1.2: Data confidentiality
Clause: 10.2.2
Summary
Confidentiality controls for IACS data shall match the classification and the harm that
disclosure would cause.
DATA 1.3: Safety system configuration mode
Clause: 10.2.3
Summary
Where safety systems are used, configuration changes shall only be made while configuration
mode is intentionally enabled, and that mode shall only be turned on when a change is
actually required.
DATA 1.4: Data retention policy
Clause: 10.2.4
Summary
Data retention — including secure disposal or purging — shall be defined for the full IACS
lifecycle.
DATA 1.5: Cryptographic mechanisms
Clause: 10.2.5
Summary
Where cryptography is used on the IACS, mechanisms shall follow commonly accepted practice.
Risk assessment relevance: Confirmed use of accepted mechanisms (for
example signed firmware only) lets the detailed assessment team score residual risk more
precisely.
See
SP and Risk Assessment.
DATA 1.6: Key management
Clause: 10.2.6
Summary
Where keyed cryptography is approved, keys shall be used, protected and retired in line with
practices accepted in both industrial and security communities.
DATA 1.7: Data integrity
Clause: 10.2.7
Summary
Integrity protection shall stop unauthorised alteration of data at rest or in motion —
whether the movement is electronic or physical — based on relevant risk.