IEC 62351-7:2017
(Main)Power systems management and associated information exchange - Data and communications security - Part 7: Network and System Management (NSM) data object models
Power systems management and associated information exchange - Data and communications security - Part 7: Network and System Management (NSM) data object models
IEC 62351-7:2017 defines network and system management (NSM) data object models that are specific to power system operations. These NSM data objects will be used to monitor the health of networks and systems, to detect possible security intrusions, and to manage the performance and reliability of the information infrastructure. The goal is to define a set of abstract objects that will allow the remote monitoring of the health and condition of IEDs (Intelligent Electronic Devices), RTUs (Remote Terminal Units), DERs (Distributed Energy Resources) systems and other systems that are important to power system operations. This new edition constitutes a technical revision and includes the following significant technical changes with respect to IEC TS 62351-7 (2010): NSM object data model reviewed and enriched; UML model adopted for NSM objects description; SNMP protocol MIBs translation included as Code Components.
The Code Components included in this IEC standard are also available as electronic machine
readable file at: https://assets.iec.ch/public/tc57/IEC_62351-7.2017_ed1.0.MIBS.1.0.light.zip?2023053143.
Gestion des systèmes de puissance et échanges d'informations associés - Sécurité des communications et des données - Partie 7: Modèles d’objets de données de gestion de réseaux et de systèmes (NSM)
IEC 62351-7:2017 définit des modèles d’objets de données de gestion de réseaux et de systèmes (NSM – network and system management) spécifiques aux opérations des systèmes de puissance. Ces objets de données NSM servent à surveiller la bonne santé des réseaux et des systèmes afin de détecter les intrusions de sécurité potentielles, et de gérer les performances et la fiabilité de l’infrastructure d’information. L’objectif est de définir un ensemble d’objets abstraits qui permet de surveiller à distance la bonne santé des appareils électroniques intelligents (IED – Intelligent Electronic Devices), des terminaux à distance (RTU – Remote Terminal Units), des systèmes de ressources énergétiques décentralisées (DER – Distributed Energy Resources) et des autres systèmes importants pour les opérations des opérations des systèmes de puissance.
Cette édition de l’IEC 62351-7 annule et remplace l’IEC TS 62351-7 parue en 2010. Cette nouvelle édition constitue une révision technique et inclut les modifications techniques majeures suivantes par rapport à l'IEC TS 62351-7:2010:
a) revue et enrichissement du modèle de données d’objets NSM;
b) adoption du modèle UML pour la description des objets NSM;
c) traduction des MIB de protocole SNMP inclus comme composants codés.
Les composants codés inclus dans la présente norme IEC sont également disponibles sous forme d’un fichier électronique lisible sur machine: http://www.iec.ch/tc57/supportdocuments/IEC_62351-7.MIBS.light.zip.
General Information
Relations
Buy Standard
Standards Content (Sample)
IEC 62351-7 ®
Edition 1.0 2017-07
INTERNATIONAL
STANDARD
colour
inside
Power systems management and associated information exchange – Data and
communications security –
Part 7: Network and System Management (NSM) data object models
All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form
or by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from
either IEC or IEC's member National Committee in the country of the requester. If you have any questions about IEC
copyright or have an enquiry about obtaining additional rights to this publication, please contact the address below or
your local IEC member National Committee for further information.
IEC Central Office Tel.: +41 22 919 02 11
3, rue de Varembé Fax: +41 22 919 03 00
CH-1211 Geneva 20 info@iec.ch
Switzerland www.iec.ch
About the IEC
The International Electrotechnical Commission (IEC) is the leading global organization that prepares and publishes
International Standards for all electrical, electronic and related technologies.
About IEC publications
The technical content of IEC publications is kept under constant review by the IEC. Please make sure that you have the
latest edition, a corrigenda or an amendment might have been published.
IEC Catalogue - webstore.iec.ch/catalogue Electropedia - www.electropedia.org
The stand-alone application for consulting the entire The world's leading online dictionary of electronic and
bibliographical information on IEC International Standards, electrical terms containing 20 000 terms and definitions in
Technical Specifications, Technical Reports and other English and French, with equivalent terms in 16 additional
documents. Available for PC, Mac OS, Android Tablets and languages. Also known as the International Electrotechnical
iPad. Vocabulary (IEV) online.
IEC publications search - www.iec.ch/searchpub IEC Glossary - std.iec.ch/glossary
The advanced search enables to find IEC publications by a 65 000 electrotechnical terminology entries in English and
variety of criteria (reference number, text, technical French extracted from the Terms and Definitions clause of
committee,…). It also gives information on projects, replaced IEC publications issued since 2002. Some entries have been
and withdrawn publications. collected from earlier publications of IEC TC 37, 77, 86 and
CISPR.
IEC Just Published - webstore.iec.ch/justpublished
Stay up to date on all new IEC publications. Just Published IEC Customer Service Centre - webstore.iec.ch/csc
details all new publications released. Available online and If you wish to give us your feedback on this publication or
also once a month by email. need further assistance, please contact the Customer Service
Centre: csc@iec.ch.
IEC 62351-7 ®
Edition 1.0 2017-07
INTERNATIONAL
STANDARD
colour
inside
Power systems management and associated information exchange – Data and
communications security –
Part 7: Network and System Management (NSM) data object models
INTERNATIONAL
ELECTROTECHNICAL
COMMISSION
ICS 33.200 ISBN 978-2-8322-4442-5
– 2 – IEC 62351-7:2017 © IEC 2017
CONTENTS
FOREWORD . 8
1 Scope . 10
2 Normative references . 10
3 Terms and definitions . 12
4 Abbreviated terms and acronyms . 13
5 Overview of Network and System Management (NSM) . 14
5.1 Objectives . 14
5.2 NSM concepts. 15
5.2.1 Simple Network Management Protocol (SNMP) . 15
5.2.2 ISO NSM categories . 15
5.2.3 NSM “data objects” for power system operations . 16
5.2.4 Other NSM protocols . 16
5.3 Communication network management . 16
5.3.1 Network configuration . 16
5.3.2 Network backup . 17
5.3.3 Communications failures and degradation . 17
5.4 Communication protocols . 18
5.5 End systems management . 18
5.6 Intrusion detection systems (IDS) . 19
5.6.1 IDS guidelines . 19
5.6.2 IDS: Passive observation techniques . 20
5.6.3 IDS: Active security monitoring architecture with NSM data objects . 20
5.7 End-to-end security . 21
5.7.1 End-to-end security concepts. 21
5.7.2 Role of NSM in end-to-end security . 22
5.8 NSM requirements: detection functions . 24
5.8.1 Detecting unauthorized access . 24
5.8.2 Detecting resource exhaustion as a denial of service (DoS) attack . 24
5.8.3 Detecting invalid buffer access DoS attacks . 25
5.8.4 Detecting tampered/malformed PDUs . 25
5.8.5 Detecting physical access disruption . 25
5.8.6 Detecting invalid network access . 25
5.8.7 Detecting coordinated attacks . 26
5.9 Abstract object and agent UML descriptions. 26
5.9.1 Purpose of UML . 26
5.9.2 Abstract types and base types . 27
5.9.3 Enumerated Types. 28
5.9.4 Abstract agents . 28
5.9.5 Unsolicited Event Notification . 31
5.9.6 UML Model extension . 31
5.10 Abstract Object UML translation to SNMP . 31
5.10.1 Simple Network Management Protocol (SNMP) . 31
5.10.2 Management information bases (MIBs) . 32
5.11 SNMP mapping of UML model Objects . 33
5.12 SNMP Security. 34
6 Abstract objects . 36
6.1 General . 36
6.2 Package Abstract Types . 37
6.2.1 General . 37
6.2.2 BooleanValue . 37
6.2.3 BooleanValueTs . 37
6.2.4 CounterTs. 37
6.2.5 CntRs . 38
6.2.6 Floating . 38
6.2.7 FloatingTs . 38
6.2.8 EntityIndex . 39
6.2.9 Integer . 39
6.2.10 IntegerTs . 39
6.2.11 InetAddress . 40
6.2.12 InetAddressType . 40
6.2.13 MacAddress . 40
6.2.14 Selector . 40
6.2.15 Timestamp . 41
6.2.16 CharString . 41
6.2.17 CharStringTs . 41
6.2.18 AbstractBaseType root class . 41
6.2.19 AbstractAgent root class . 42
6.3 Package EnumeratedTypes . 42
6.3.1 General . 42
6.3.2 AppDatStKind enumeration . 42
6.3.3 PhyHealthKind enumeration. 42
6.3.4 ExtKind enumeration . 42
6.3.5 IntKind enumeration. 43
6.3.6 LnkKind enumeration . 43
6.3.7 PSPAccKind enumeration . 43
6.3.8 ProtIdKind enumeration . 43
6.3.9 EventKind enumeration . 44
6.3.10 TimSyncIssueKind enumeration . 44
6.3.11 SecurityProfileKind enumeration . 45
6.3.12 TimSyncSrcKind enumeration . 45
6.3.13 AppDatStType . 45
6.3.14 PhyHealthType . 46
6.3.15 ExtType . 46
6.3.16 IntType . 46
6.3.17 EventType . 46
6.3.18 PSPAccType . 47
6.3.19 ProtIdType . 47
6.3.20 TimSyncIssueType . 47
6.3.21 SecurityProfileType . 47
6.3.22 TimSyncSrcType . 48
6.3.23 LnkType . 48
7 Agents . 48
7.1 Package Overview . 48
7.2 Package Environmental Agent . 50
7.2.1 General .
...
Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.