{"id":2913,"date":"2021-09-10T09:58:39","date_gmt":"2021-09-10T09:58:39","guid":{"rendered":"https:\/\/www.publiteconline.it\/controlloemisura\/?p=2913"},"modified":"2025-06-24T15:38:05","modified_gmt":"2025-06-24T15:38:05","slug":"safety-and-security-meet","status":"publish","type":"post","link":"https:\/\/www.publiteconline.it\/controlloemisura\/safety-and-security-meet\/","title":{"rendered":"Safety and Security Meet"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">In the industry world, where production and IT become more and more inextricably linked, security challenges are constantly evolving. <a href=\"https:\/\/www.phoenixcontact.com\/online\/portal\/it?1dmy&amp;urile=wcm:path:\/itit\/web\/home\">Phoenix Contact<\/a>, which supports companies in the flexible combination of safety and security technology, tells us about it<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The importance of the safety technology installed in machines and systems steadily increases over the entire life cycle of the application. However, as networking of automation systems with the IT world is becoming more and more commonplace, scenarios are likely to arise where a different approach is required, especially for safety applications. As production and IT become more and more inextricably linked in the Internet of Things within the framework of the future project Industrie 4.0, the security challenges are also growing.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"150\" src=\"https:\/\/www.publiteconline.it\/controlloemisura\/wp-content\/uploads\/2021\/09\/1-13.jpg\" alt=\"The various steps in the risk assessment process in accordance with NAMUR NA 163.\" class=\"wp-image-2914\" title=\"The various steps in the risk assessment process in accordance with NAMUR NA 163.\" srcset=\"https:\/\/www.publiteconline.it\/controlloemisura\/wp-content\/uploads\/2021\/09\/1-13.jpg 800w, https:\/\/www.publiteconline.it\/controlloemisura\/wp-content\/uploads\/2021\/09\/1-13-300x56.jpg 300w, https:\/\/www.publiteconline.it\/controlloemisura\/wp-content\/uploads\/2021\/09\/1-13-768x144.jpg 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><figcaption>The various steps in the risk assessment process in accordance with NAMUR NA 163.<\/figcaption><\/figure><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Functional and security safety: indirect effects on the end product<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The aspect of functional safety refers to the safety component of a system, that relies on the correct function of the safety-related (control) system and other risk-reducing measures. In this case, the controller performs the task of initiating the safe state when a critical error occurs.<br>The requirements for the quality of safety-relevant control components are described in the B-standard EN ISO 13849 and the IEC series 61508\/61511\/62061.<br>Depending on the degree of risk, corresponding risk-reducing measures are classified into to different safety levels &#8211; Performance Level (PL) or Safety Integrity Level (SIL). In contrast to functional safety, security protects goods from detrimental impairment as a result of intentional or inadvertent attacks on the availability, integrity and confidentiality of their data. This involves the use of preventative or reactive technical and\/or organizational measures.<br>If security aspects in the area of safety are disregarded, this can not only have direct effects on production facilities, it can also indirectly affect the production process and therefore the end product. In the context of pharmaceutical products and safety-relevant components for the automotive industry, it is easy to see how the effects on consumers could be significant. The IEC 61511-1 therefore requires an IT risk assessment to be carried out for safety equipment in the process industry. If operators of PCE (process control engineering) safety equipment perform the IT risk assessment as specified in the attached NAMUR NA worksheets and implement the measures identified, it is likely they will have assessed their PCE safety equipment in accordance with the latest technical standards and will therefore have fulfilled their duty-of-care obligations.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"565\" src=\"https:\/\/www.publiteconline.it\/controlloemisura\/wp-content\/uploads\/2021\/09\/2-9.jpg\" alt=\"Subdivision of PCE safety equipment into various zones.\" class=\"wp-image-2915\" title=\"Subdivision of PCE safety equipment into various zones.\" srcset=\"https:\/\/www.publiteconline.it\/controlloemisura\/wp-content\/uploads\/2021\/09\/2-9.jpg 800w, https:\/\/www.publiteconline.it\/controlloemisura\/wp-content\/uploads\/2021\/09\/2-9-300x212.jpg 300w, https:\/\/www.publiteconline.it\/controlloemisura\/wp-content\/uploads\/2021\/09\/2-9-768x542.jpg 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><figcaption>Subdivision of PCE safety equipment \ninto various zones.<\/figcaption><\/figure><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Attackers\u2019 methods of finding vulnerabilities are constantly evolving<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When considering functional safety and access security, the potential risk must initially be considered based on a risk assessment or IT threat analysis. Here, a considerable difference in approaches is already evident. While the risks that design engineers need to consider within the scope of the risk assessment in accordance with the Machinery Directive \u2013 mechanical or electrical hazards for example \u2013 tend to remain the same, the environment in which IT security experts find themselves is constantly changing. In the latter case, attackers are always actively looking for ways to exploit vulnerabilities which would be considered systematic errors in the area of functional safety. Another important aspect to consider is the \u201chuman factor\u201d. The expression \u201cforeseeable misuse\u201d is used in the field of machine safety, for example, to describe situations where safety equipment \u2013 such as door switches \u2013 are tampered with by operating personnel. With large-scale cyber attacks on industrial systems, on the other hand, it must be assumed that a high degree of criminal energy is exerted in these cases.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"644\" src=\"https:\/\/www.publiteconline.it\/controlloemisura\/wp-content\/uploads\/2021\/09\/3-9.jpg\" alt=\"The system operator can access the safety system data in real time via the Proficloud.\" class=\"wp-image-2916\" title=\"The system operator can access the safety system data in real time via the Proficloud.\" srcset=\"https:\/\/www.publiteconline.it\/controlloemisura\/wp-content\/uploads\/2021\/09\/3-9.jpg 800w, https:\/\/www.publiteconline.it\/controlloemisura\/wp-content\/uploads\/2021\/09\/3-9-300x242.jpg 300w, https:\/\/www.publiteconline.it\/controlloemisura\/wp-content\/uploads\/2021\/09\/3-9-768x618.jpg 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><figcaption>The system operator can access the safety system data \nin real time via the Proficloud.<\/figcaption><\/figure><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">A worksheet for IT risk assessment<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To safeguard the product life cycle of safety-oriented systems or components, manufacturers, system integrators and operators are required within the scope of \u201cFunctional Safety Management\u201d, to adopt an approach to quality management that reflects the requirements of the situation in accordance with IEC 61508. A comparable solution for this exists in the security world in the form of \u201cInformation Security Management\u201d in accordance with ISO 27000. The worksheet published by NAMUR entitled \u201cIT risk assessment of PCE safety equipment\u201d adopts an initial pragmatic approach which leads in this direction. It describes an IT risk assessment method which uses the IEC 62443 security standard as its starting point, to provide a basis for increasing the capability of the PCE safety equipment of averting IT threats. To this end, the three steps in phase 1 were performed once as an example for one system, which reflects the systems typically found in the NAMUR member companies. This allows the user to gauge the usefulness of the method for the PCE safety equipment to be assessed. The fourth step \u2013 monitoring implementation of the measures and documenting the IT security requirements and general conditions \u2013 must be carried out individually for all items of PCE safety equipment to be evaluated and constitutes phase II (Figure 1).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Subdividing the system into three zones to avoid environmental repercussions<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">From the hardware and software perspective, the system being examined can therefore be subdivided into three zones. The core PCE safety equipment in zone A comprises the PCE safety equipment as defined in the IEC 61511-1. This includes the logic system, the input and output modules including remote I\/O, and also the actuators and sensors. Components that are not necessary for implementation of the safety function but could nonetheless influence the behavior of the core PCE safety equipment are allocated to the extended PCE safety equipment in zone B. Components and systems that do not belong either directly or indirectly in the same category as the PCE safety equipment, but could be linked to the safety function belong in the zone referred to as \u201cenvironment\u201d. This could be reset requirements or the visualization of the status of the safety function (Figure 2). The common objective of the zones is to ensure that the functional integrity of the safety equipment is not compromised by feedback effects from the environment.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the industry world, where production and IT become more and more inextricably linked, security challenges are constantly evolving. Phoenix Contact, which supports companies in the flexible combination of safety and security technology, tells us about it The importance of the safety technology installed in machines and systems steadily increases over the entire life cycle &hellip;<\/p>\n","protected":false},"author":4,"featured_media":2911,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_seopublitec_title":"","_seopublitec_meta_desc":"Nel mondo dell\u2019industria, in cui produzione e IT sono sempre pi\u00f9 connessi, le sfide per la sicurezza informatica si evolvono di continuo. Ce ne parla Phoenix Contact, che supporta le aziende nella combinazione flessibile della tecnologia Safety e Security","_seopublitec_keyphrases":"Phoenix Contact","_seopublitec_canonical":"","_seopublitec_noindex":false,"_seopublitec_nofollow":false,"_seopublitec_og_title":"","_seopublitec_og_desc":"","_seopublitec_twitter_title":"","_seopublitec_twitter_desc":"","_seopublitec_twitter_image":"","_seopublitec_og_image":"","_seopublitec_twitter_card":"","_seopublitec_cornerstone":false,"_seopublitec_score":"{\"overall\":\"ok\",\"keyphrases\":{\"Phoenix Contact\":\"ok\"},\"readability\":\"ok\"}"},"categories":[27],"tags":[734,1455,343,942],"class_list":["post-2913","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tecnologie","tag-cyber-security","tag-functional-security","tag-phoenix-contact-en","tag-software-en"],"openstation_lock":null,"openstation_contributors":[],"openstation_attached_media":[2911,2914,2915,2916],"_links":{"self":[{"href":"https:\/\/www.publiteconline.it\/controlloemisura\/wp-json\/wp\/v2\/posts\/2913","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.publiteconline.it\/controlloemisura\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.publiteconline.it\/controlloemisura\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.publiteconline.it\/controlloemisura\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.publiteconline.it\/controlloemisura\/wp-json\/wp\/v2\/comments?post=2913"}],"version-history":[{"count":1,"href":"https:\/\/www.publiteconline.it\/controlloemisura\/wp-json\/wp\/v2\/posts\/2913\/revisions"}],"predecessor-version":[{"id":2918,"href":"https:\/\/www.publiteconline.it\/controlloemisura\/wp-json\/wp\/v2\/posts\/2913\/revisions\/2918"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.publiteconline.it\/controlloemisura\/wp-json\/wp\/v2\/media\/2911"}],"wp:attachment":[{"href":"https:\/\/www.publiteconline.it\/controlloemisura\/wp-json\/wp\/v2\/media?parent=2913"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.publiteconline.it\/controlloemisura\/wp-json\/wp\/v2\/categories?post=2913"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.publiteconline.it\/controlloemisura\/wp-json\/wp\/v2\/tags?post=2913"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}