General Information

Abstract

IEC TS 63074:2023 identifies the relevant aspects of the IEC 62443 series related to security threats and vulnerabilities that are considered for the design and implementation of safety-related control systems (SCS) which can lead to the loss of the ability to maintain safe operation of a machine.
Typical security aspects related to the machine with potential relation to SCS are:
– vulnerabilities of the SCS either directly or indirectly through the other parts of the machine which can be exploited by security threats that can result in security attacks (security breach);
– influence on the safety characteristics and ability of the SCS to properly perform its function(s);
– typical use case definition and application of a corresponding threat model.
Non-safety-related aspects of security threats and vulnerabilities are not considered in this document.
The focus of this document is on intentional malicious actions. However, intentional hardware manipulation (e.g. wiring, exchange of components) or foreseeable misuse by physical manipulation of SCS (e.g. physical bypass) is not considered in this document.
This document does not cover security requirements for information technology (IT) products and for the design of devices used in the SCS (e.g., product specific standards can be available, such as IEC TS 63208).

Status
Published
Publication Date
08-Feb-2023
Drafting Committee
WG 15 - TC 44/WG 15
Current Stage
PPUB - Publication issued
Start Date
09-Feb-2023
Completion Date
20-Mar-2023

Buy Documents

Technical specification

IEC TS 63074:2023 - Safety of machinery - Security aspects related to functional safety of safety-related control systems Released:2/9/2023

ISBN:978-2-8322-6468-3
English language (30 pages)
sale 15% off
Preview
sale 15% off
Preview

Overview

IEC TS 63074:2023 - "Safety of machinery – Security aspects related to functional safety of safety‑related control systems" - is a Technical Specification from the IEC that identifies how security threats and vulnerabilities (from the IEC 62443 family) can affect the functional safety of safety‑related control systems (SCS) in machines. The document focuses on intentional malicious actions that can lead to loss of the ability to maintain safe operation, and maps security considerations to safety objectives without covering general IT product requirements or product design standards.

Key topics

  • Scope & focus: Security aspects that can influence the safety characteristics and performance of SCS; intentional malicious actions are the primary focus (physical bypass and certain hardware manipulation are excluded).
  • Security risk assessment: Guidance on applying threat modelling and risk‑based approaches to identify security risks that impact safety integrity.
  • Security countermeasures: High‑level measures relevant to functional safety, including:
    • Identification and authentication
    • Use control
    • System integrity
    • Data confidentiality
    • Restricted data flow
    • Timely response to events
    • Resource availability
  • Cybersecurity and functional safety: New material (Clause 6) addressing protection against corruption, attack vectors (network architecture, portable devices, wireless, remote access, direct physical connections) and mitigation approaches such as multi‑factor authentication and network segregation.
  • Verification & maintenance: Emphasis on ongoing verification, maintenance of security countermeasures and information flow among device suppliers, machine manufacturers, integrators and end users.
  • Threat modelling examples and triggers: Informative annexes with threat evaluation, example threats to safety‑related devices and triggers that require reassessment.

Practical applications

IEC TS 63074:2023 is practical for organizations that need to align cybersecurity activities with functional safety obligations:

  • Use in design and implementation of safety‑related control systems (SCS) to ensure security risks do not degrade safety performance.
  • Input to safety and cybersecurity risk assessments during machine lifecycle (design, integration, use, maintenance).
  • Guidance for selecting and specifying security countermeasures that have direct relevance to safety integrity and availability.
  • Basis for documenting information flows between suppliers, integrators and users to support secure machine operation.

Who should use this standard

  • Machine OEMs and designers
  • Safety engineers and functional safety assessors
  • Industrial control system integrators
  • Cybersecurity engineers working in manufacturing and automation
  • Asset owners, maintenance teams and compliance officers

Related standards

  • IEC 62443 series (industrial automation cybersecurity)
  • IEC 62061, IEC 61508 (functional safety / safety integrity)
  • ISO 13849‑1 (Performance Level for safety parts of control systems)
  • IEC TS 63208 (product‑specific device design - referenced as outside scope)

Keywords: IEC TS 63074:2023, safety of machinery, functional safety, safety‑related control systems, IEC 62443, cybersecurity, security risk assessment, threat modelling.

Relations

Effective Date
05-Sep-2023

Buy Documents

Technical specification

IEC TS 63074:2023 - Safety of machinery - Security aspects related to functional safety of safety-related control systems Released:2/9/2023

ISBN:978-2-8322-6468-3
English language (30 pages)
sale 15% off
Preview
sale 15% off
Preview

Get Certified

Connect with accredited certification bodies for this standard

Intertek Testing Services NA Inc.

Intertek certification services in North America.

ANAB United States Verified

NSF International

Global independent organization facilitating standards development and certification.

ANAB United States Verified

UL Solutions

Global safety science company with testing, inspection and certification.

ANAB United States Verified

Sponsored listings

Frequently Asked Questions

IEC TS 63074:2023 is a technical specification published by the International Electrotechnical Commission (IEC). Its full title is "Safety of machinery - Security aspects related to functional safety of safety-related control systems". This standard covers: IEC TS 63074:2023 identifies the relevant aspects of the IEC 62443 series related to security threats and vulnerabilities that are considered for the design and implementation of safety-related control systems (SCS) which can lead to the loss of the ability to maintain safe operation of a machine. Typical security aspects related to the machine with potential relation to SCS are: – vulnerabilities of the SCS either directly or indirectly through the other parts of the machine which can be exploited by security threats that can result in security attacks (security breach); – influence on the safety characteristics and ability of the SCS to properly perform its function(s); – typical use case definition and application of a corresponding threat model. Non-safety-related aspects of security threats and vulnerabilities are not considered in this document. The focus of this document is on intentional malicious actions. However, intentional hardware manipulation (e.g. wiring, exchange of components) or foreseeable misuse by physical manipulation of SCS (e.g. physical bypass) is not considered in this document. This document does not cover security requirements for information technology (IT) products and for the design of devices used in the SCS (e.g., product specific standards can be available, such as IEC TS 63208).

IEC TS 63074:2023 identifies the relevant aspects of the IEC 62443 series related to security threats and vulnerabilities that are considered for the design and implementation of safety-related control systems (SCS) which can lead to the loss of the ability to maintain safe operation of a machine. Typical security aspects related to the machine with potential relation to SCS are: – vulnerabilities of the SCS either directly or indirectly through the other parts of the machine which can be exploited by security threats that can result in security attacks (security breach); – influence on the safety characteristics and ability of the SCS to properly perform its function(s); – typical use case definition and application of a corresponding threat model. Non-safety-related aspects of security threats and vulnerabilities are not considered in this document. The focus of this document is on intentional malicious actions. However, intentional hardware manipulation (e.g. wiring, exchange of components) or foreseeable misuse by physical manipulation of SCS (e.g. physical bypass) is not considered in this document. This document does not cover security requirements for information technology (IT) products and for the design of devices used in the SCS (e.g., product specific standards can be available, such as IEC TS 63208).

IEC TS 63074:2023 is classified under the following ICS (International Classification for Standards) categories: 13.110 - Safety of machinery; 29.020 - Electrical engineering in general. The ICS classification helps identify the subject area and facilitates finding related standards.

IEC TS 63074:2023 has the following relationships with other standards: It is inter standard links to IEC TR 63074:2019. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.

IEC TS 63074:2023 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)