Overview
IEC GUIDE 120:2018 - Security aspects – Guidelines for their inclusion in publications is a non‑mandatory IEC guide that tells standards writers and technical committees what security topics should be covered in IEC publications and how to implement them. The Guide is intended as a practical checklist for the combination of publications used when implementing electrotechnical systems. It explicitly includes what is commonly called cyber security and excludes non‑electrotechnical societal security except where it directly interacts with electrotechnical security.
Key topics and technical requirements
IEC GUIDE 120:2018 organizes guidance around publication types, lifecycle concerns and domain applicability. Core topics covered include:
- Categorization of publications (base, group, product, guidance, test) to help authors position security requirements.
- Terminology and primary sources for consistent use of security and cyber security terms.
- Security risk assessment: iterative risk assessment, scenario analysis, risk mitigation strategy and validation.
- Interrelation with functional safety: identifying how security risks can impact safety‑related control systems.
- Lifecycle and holistic system view: design, development, operation and maintenance considerations.
- Defence‑in‑depth strategies and selected technical/organizational measures.
- Vulnerability handling and secure supply chain considerations.
- Security management and conformity assessment: aligning standards development with assessment needs.
- Practical guidance for dealing with greenfield and brownfield deployments.
The Guide also points standards writers to normative and relevant references (e.g., ISO/IEC Directives, IEC TS 62443, ISO/IEC 27000 family) to ensure alignment with accepted cyber security practices.
Practical applications - who uses this standard
IEC GUIDE 120 is aimed at anyone involved in producing, applying or assessing IEC publications and electrotechnical systems, including:
- Standards committees, technical writers and editors - to include appropriate security clauses in standards.
- Product developers and system integrators - to ensure standards used for procurement and design address security throughout the lifecycle.
- Cybersecurity engineers and architects - for mapping security requirements to tests, product standards and domain guidance.
- Conformity assessment bodies and regulators - for understanding how security content is organized in IEC publications.
- Asset owners and operators - when combining standards to implement secure, resilient systems.
Related standards
Relevant references and complementary documents include:
- ISO/IEC Directives Part 2 (document structure and drafting)
- IEC TS 62443 series (industrial automation and control systems security)
- ISO/IEC 27000 family (information security management)
- IEC 60050 and ISO/IEC GUIDE 51 (terminology and safety concepts)
Use IEC GUIDE 120:2018 as a practical roadmap to integrate security aspects and cyber security consistently and coherently across electrotechnical standards and system implementations.