PD IEC/TR 62351-13 is a safety standard on power systems management and associated information exchange.
PD IEC/TR 62351-13, which is a technical report, provides guidelines on what security topics could or should be covered in standards and specifications (IEC or otherwise) that are to be used in the power industry, and the audience is, therefore, the developers of standards and specifications.
Note: Out-of-scope are explicit methods for cyber security in product development, implementations, or operations.
PD IEC/TR 62351-13 on data and communications security is relevant to:
PD IEC/TR 62351-13 provides guidelines on what security topics should be covered in standards and specifications (IEC or otherwise) that are to be used in the power industry. These guidelines cannot be prescriptive for every standard, since individual standards and specifications may legitimately have vastly different focuses, but it should be expected that the combination of such standards and specifications used in any implementation should cover these security topics. These guidelines are therefore to be used as a checklist for the combination of standards and specifications used in implementations of systems.
The security requirements for human users and software applications are different from the purely technical security requirements found in many communication and device standards.
For user security standards, more emphasis should be on “policy and procedures” and “roles and authorization” rather than “bits and bytes” cryptographic technologies that should be included in Information and Communications Technology (ICT).
PD IEC/TR 62351-13 is structured into four sections:
Overall, PD IEC/TR 62351-13 is helpful as it provides guidance on the security topics to be covered in standards and specifications for data and communications security.
IEC TR 62351-13:2016