Cybersecurity Design + Implementation
Participating in this 4,5 days training course will enhance the skill set of those involved to fulfill their responsibilities and undertake activities in compliance with industry recognized security standards such as the IEC 62443, to:
- reduce the risk of a successful cyber attack
- satisfy legal and regulatory requirements
- meet the organisation’s system cybersecurity and business objectives.
Participants will understand:
- The principles and concepts as provided with the international agreed standard IEC 62443
- The concepts and principles behind international standards and guidelines that cover the area of cyber security and how and when to apply them including:
- Security Risk Assessment (SRA) - IEC 61511-1, ISA TR84.00.09 & IEC 62443
- Cybersecurity Management System (CSMS) – IEC 62443
- Information Security Management System (ISMS) - ISO 27000 series
- Overview of ICS Threats & Vulnerabilities - NIST SP 800 Series
- Cyber Resilience Act (CRA)
- EU Directive on Network and Information Systems (NIS2).
- The IACS cybersecurity lifecycle and the key roles and responsibilities
- Security risk assessment and the interface with security requirements specification
- The IEC 62443 foundational requirements’ countermeasures & their implementation
- High-level and low-level design requirements
- Cybersecurity verification and validation requirements
- The requirements for cybersecurity documents in order to demonstrate conformance.
Target Group
Functional, Process and Technical Safety Engineers, Control and Instrument Engineers and Managers, Process Engineers, Operations personnel and managers, maintenance staff, consultants, advisors and persons involved in management, engineering, operations and safety of process operations as well as persons with operational experience and who are currently involved in cybersecurity activities on their facilities from within the following process industry user groups:
- Asset Owners / End User
- Engineering Contractors / EPCs
- Power and Automation system integrators
- Service providers
Course Objectives
The objective of this course is to provide participants with a fundamental understanding of the requirements of IACS Cybersecurity design and implementation with respect to the security measures identified in IEC 62443 and to understand:
- The role and the process of Security Risk Assessment (SRA) in gaining an understanding of the security risks and required foundational requirement security measures.
- The relationship between Security Level (SL)-T and Cybersecurity Requirements Specification (CRS) to the design and implementation of security countermeasures that achieve the security requirements needed of the determined SL.
- How those security measures / countermeasures should be implemented, verified and validated.
- The importance of Cybersecurity Lifecyle Management to gain and maintain SL.
The course includes practical case studies that will be developed by candidates across the four days of the training course taking the delegate through the IEC 62443 design and implementation process. The course follows a modular structure and is typically delivered as a tutor led classroom session with case studies.
Agenda
Exam
A three (3) hour exam existing of 2 parts.
Part 1: Multiple-choice questions
Part 2: Open questions
The pass score criterion is 70% overall score covering both exam parts.
Eligibility Requirements
In accordance with the TÜV Rheinland Functional Safety and Cyber Security Training Program:
Experience:
- A minimum of 3 years of industrial experience in a related field
(e.g. Control & Instrumentation, process engineering, IT/OT, functional safety or cyber security).
Qualifications:
- Technical Education or Diploma (University degree) or vocational course qualification
or
- Equivalent engineer level experience and responsibilities status as certified by employer / engineering institution om a reference letter.
CySec Specialist (TÜV Rheinland) Certificate
Successful participants, who have the requisite experience and who pass both parts of the Cybersecurity design and implementation exam, will be eligible for the prestigious CySec Specialist (TÜV Rheinland) certificate in Design & Implementation.
Holders of this certificate will be listed at the TÜV Rheinland Certipedia website.
Costs
€ 2.690 + VAT
Includes: exam and CySec Specialist (TÜV Rheinland) certificate (if requirements are fulfilled and the exam is passed), training proceedings, lunch and beverages.
€ 2.390 + VAT
Without exam and CySec Specialist (TÜV Rheinland) certificate.
Includes: training proceedings, lunch and refreshments.