prEN IEC 62351-7:2024
(Main)Power systems management and associated information exchange - Data and communications security - Part 7: Network and system management (NSM) data object models
Power systems management and associated information exchange - Data and communications security - Part 7: Network and system management (NSM) data object models
Datenmodelle, Schnittstellen und Informationsaustausch für Planung und Betrieb von Energieversorgungsunternehmen – Daten- und Kommunikationssicherheit - Teil 7: Datenobjektmodelle für Netzwerk- und Systemmanagement (NSM)
Gestion des systèmes de puissance et échanges d'informations associés - Sécurité des communications et des données - Partie 7: Modèles d’objets de données de gestion de réseaux et de systèmes (NSM)
Upravljanje elektroenergetskega sistema in pripadajoča izmenjava informacij - Varnost podatkov in komunikacij - 7. del: Podatkovni modeli pri upravljanju omrežij in sistemov (NSM)
General Information
Relations
Standards Content (Sample)
SLOVENSKI STANDARD
01-april-2024
Upravljanje elektroenergetskega sistema in pripadajoča izmenjava informacij -
Varnost podatkov in komunikacij - 7. del: Podatkovni modeli pri upravljanju
omrežij in sistemov (NSM)
Power systems management and associated information exchange - Data and
communications security - Part 7: Network and system management (NSM) data object
models
Datenmodelle, Schnittstellen und Informationsaustausch für Planung und Betrieb von
Energieversorgungsunternehmen – Daten- und Kommunikationssicherheit - Teil 7:
Datenobjektmodelle für Netzwerk- und Systemmanagement (NSM)
Gestion des systèmes de puissance et échanges d'informations associés - Sécurité des
communications et des données - Partie 7: Modèles d’objets de données de gestion de
réseaux et de systèmes (NSM)
Ta slovenski standard je istoveten z: prEN IEC 62351-7:2024
ICS:
29.240.30 Krmilna oprema za Control equipment for electric
elektroenergetske sisteme power systems
35.240.50 Uporabniške rešitve IT v IT applications in industry
industriji
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
57/2639/CDV
COMMITTEE DRAFT FOR VOTE (CDV)
PROJECT NUMBER:
IEC 62351-7 ED2
DATE OF CIRCULATION: CLOSING DATE FOR VOTING:
2024-02-09 2024-05-03
SUPERSEDES DOCUMENTS:
57/2583/CD, 57/2604A/CC
IEC TC 57 : POWER SYSTEMS MANAGEMENT AND ASSOCIATED INFORMATION EXCHANGE
SECRETARIAT: SECRETARY:
Germany Mr Heiko Englert
OF INTEREST TO THE FOLLOWING COMMITTEES: PROPOSED HORIZONTAL STANDARD:
Other TC/SCs are requested to indicate their interest, if any, in
this CDV to the secretary.
FUNCTIONS CONCERNED:
EMC ENVIRONMENT QUALITY ASSURANCE SAFETY
SUBMITTED FOR CENELEC PARALLEL VOTING NOT SUBMITTED FOR CENELEC PARALLEL VOTING
Attention IEC-CENELEC parallel voting
The attention of IEC National Committees, members of CENELEC,
is drawn to the fact that this Committee Draft for Vote (CDV) is
submitted for parallel voting.
The CENELEC members are invited to vote through the CENELEC
online voting system.
This document is still under study and subject to change. It should not be used for reference purposes.
Recipients of this document are invited to submit, with their comments, notification of any relevant patent rights of which they are
aware and to provide supporting documentation.
Recipients of this document are invited to submit, with their comments, notification of any relevant “In Some Countries” clau ses to be
included should this proposal proceed. Recipients are reminded that the CDV stage is the final stage for submitting ISC c lauses.
(SEE AC/22/2007 OR NEW GUIDANCE DOC).
TITLE:
Power systems management and associated information exchange - Data and communications security - Part
7: Network and System Management (NSM) data object models
PROPOSED STABILITY DATE: 2025
NOTE FROM TC/SC OFFICERS:
electronic file, to make a copy and to print out the content for the sole purpose of preparing National Committee positions.
You may not copy or "mirror" the file or printed version of the document, or any part of it, for any other purpose without
permission in writing from IEC.
57/2639/CDV – 2 – IEC CDV 62351-7© IEC: 2024
CONTENTS
FOREWORD . 9
1 Scope . 11
2 Normative references . 11
3 Terms and definitions . 13
4 Abbreviated terms and acronyms . 14
5 Overview of Network and System Management (NSM) . 14
5.1 Objectives . 14
5.2 NSM concepts. 16
5.2.1 Simple Network Management Protocol (SNMP) . 16
5.2.2 ISO NSM categories . 16
5.2.3 NSM “data objects” for power system operations . 17
5.2.4 Other NSM protocols . 17
5.3 Communication network management . 17
5.3.1 Network configuration . 17
5.3.2 Network backup . 18
5.3.3 Communications failures and degradation . 18
5.4 Communication protocols . 18
5.5 End systems management . 19
5.6 Intrusion detection systems (IDS) . 20
5.6.1 IDS guidelines . 20
5.6.2 IDS: Passive observation techniques . 21
5.6.3 IDS: Active security monitoring architecture with NSM data objects . 21
5.7 End-to-end security . 22
5.7.1 End-to-end security concepts. 22
5.7.2 Role of NSM in end-to-end security . 23
5.8 NSM requirements: detection functions . 25
5.8.1 Detecting unauthorized access . 25
5.8.2 Detecting resource exhaustion as a denial of service (DoS) attack . 25
5.8.3 Detecting invalid buffer access DoS attacks . 26
5.8.4 Detecting tampered/malformed PDUs . 26
5.8.5 Detecting physical access disruption . 26
5.8.6 Detecting invalid network access . 26
5.8.7 Detecting coordinated attacks . 27
5.9 Abstract object and agent UML descriptions. 27
5.9.1 Purpose of UML . 27
5.9.2 Abstract types and base types . 28
5.9.3 Enumerated Types. 28
5.9.4 Abstract agents . 29
5.9.5 Unsolicited Event Notification . 32
5.9.6 UML Model extension . 32
5.10 Abstract Object UML translation to SNMP . 32
5.10.1 Simple Network Management Protocol (SNMP) . 32
5.10.2 Management information bases (MIBs) . 32
5.11 SNMP mapping of UML model Objects . 33
5.12 SNMP Security. 35
IEC CDV 62351-7© IEC: 2024 – 3 – 57/2639/CDV
6 Abstract objects . 37
6.1 General . 37
6.2 Package Abstract Types . 38
6.2.1 General . 38
6.2.2 BooleanValue . 38
6.2.3 BooleanValueTs . 38
6.2.4 CounterTs. 38
6.2.5 CntRs . 39
6.2.6 Floating . 39
6.2.7 FloatingTs . 39
6.2.8 EntityIndex . 40
6.2.9 Integer . 40
6.2.10 IntegerTs . 40
6.2.11 InetAddress . 41
6.2.12 InetAddressType . 41
6.2.13 MacAddress . 41
6.2.14 Selector . 41
6.2.15 Timestamp . 42
6.2.16 CharString . 42
6.2.17 CharStringTs . 42
6.2.18 AbstractBaseType root class . 43
6.2.19 AbstractAgent root class . 43
6.3 Package EnumeratedTypes . 43
6.3.1 General . 43
6.3.2 AppDatStKind enumeration . 43
6.3.3 PhyHealthKind enumeration. 43
6.3.4 ExtKind enumeration . 43
6.3.5 IntKind enumeration. 44
6.3.6 LnkKind enumeration . 44
6.3.7 PSPAccKind enumeration . 44
6.3.8 ProtIdKind enumeration . 44
6.3.9 EventKind enumeration . 45
6.3.10 TimSyncIssueKind enumeration . 45
6.3.11 SecurityProfileKind enumeration . 45
6.3.12 TimSyncSrcKind enumeration . 46
6.3.13 AppDatStType . 46
6.3.14 PhyHealthType . 47
6.3.15 ExtType . 47
6.3.16 IntType . 47
6.3.17 EventType . 47
6.3.18 PSPAccType . 48
6.3.19 ProtIdType . 48
6.3.20 TimSyncIssueType . 48
6.3.21 SecurityProfileType . 48
6.3.22 TimSyncSrcType . 49
6.3.23 LnkType . 49
7 Agents . 49
7.1 Package Overview . 49
57/2639/CDV – 4 – IEC CDV 62351-7© IEC: 2024
7.2 Package Environmental Agent . 50
7.2.1 General
...
Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.