1 Scope
1.1 General
This document establishes requirements and provides guidance for the development and
management of effective computer security programmes for I&C programmable digital systems. Inherent to these requirements and guidance
is the criterion that the power plant I&C programmable digital system security programme complies with the applicable country’s requirements.
This document defines adequate measures for the prevention of, detection of and reaction
to malicious acts by digital means ( cyberattacks ) on I&C programmable digital systems. This includes any unsafe situation, equipment
damage or plant performance degradation that could result from such an act, such as:
— malicious modifications affecting system integrity ;
— malicious interference with information, data or resources that could compromise the
delivery of or performance of the required I&C programmable digital functions;
— malicious interference with information, data or resources that could compromise operator
displays or lead to loss of management of I&C programmable digital systems;
— mal...