Overview
IEC Guide 120:2023 - Security aspects – Guidelines for their inclusion in publications provides structured guidance for how security (including what is commonly called cybersecurity) should be addressed in IEC publications. It helps IEC technical committees and standards authors determine which security topics to include, how to implement them in standards, and how to use multiple publications together as a checklist when implementing systems. The Guide applies to IEC publication types (International Standards, Technical Reports, Technical Specifications, Guides) and excludes non‑electrotechnical societal security except where it directly interacts with electrotechnical security.
Key Topics
- Publication categorization: guidance on classifying publications (basic/horizontal, group, product, guidance, test) to ensure consistent treatment of security across domains.
- Terminology alignment: harmonization with IEC Guide 108:2019 and recommended primary/secondary sources for consistent security terms.
- Lifecycle and holistic view: adoption of a lifecycle approach and system-level (holistic) perspective for security requirements and resilience.
- Security risk assessment: iterative risk assessment, scenario analysis, risk mitigation strategy, validation, and maintaining safe operation.
- Security controls and strategies: defence‑in‑depth, vulnerability handling, security management, and selected measures for protecting systems.
- Supply chain and deployment considerations: guidance on supply‑chain security, and for both greenfield and brownfield environments.
- Interrelation with functional safety: principles for aligning security measures with functional safety requirements.
- Conformity assessment: considerations when writing standards that may be subject to conformity assessment.
- Practical development advice: recommendations for publication writers, mapping of relevant publications, and decision flow charts to support consistent standardization.
Practical Applications
- Use as a checklist when developing or updating IEC standards to ensure security aspects are covered consistently.
- Guide standards writers in adding security clauses to product standards, group standards, or domain‑specific documents.
- Help conformity assessment bodies and implementers understand the intended security scope and risk‑based expectations in IEC publications.
- Support system architects, product developers, and integrators to align design and procurement decisions with standardized security guidance and lifecycle practices.
Who Should Use This Standard
- IEC technical committees, subcommittees and systems committees
- Standards writers and editors
- Product and system developers in electrotechnical domains
- Conformity assessment and certification bodies
- Security program managers responsible for standards compliance
Related Standards
- IEC Guide 108:2019 (terminology alignment)
- Relevant IEC horizontal and domain‑specific standards referenced within Guide 120 for detailed controls, testing and implementation (see Guide 120 bibliography and mapping tables).
Keywords: IEC Guide 120, cybersecurity, security aspects, IEC publications, security risk assessment, defence-in-depth, supply chain security, lifecycle approach, functional safety, standardization.