The evolution of standards and legislation
ICS cybersecurity has thrived in recent years. The domain has made significant strides forward when it comes to improving the maturity of the market and ensuring that the majority of these assets are deemed and classified as CIs in many countries. While the legislation and its level of enforcement vary widely forms depending on the regions and sectors, in this chapter, we will focus on a few examples that aim to cover all regions.
The legislations are usually mandated by competent authorities at a national level and are imposed in the form of acts, regulations, or directives. These standards are industry-specific and usually initiated by professional associations or working groups and might also consist of local or international members. Some of the standards are considered state-of-the-art or good engineering practices:
Figure 7.1 – Regulatory hierarchy concerning ICS cybersecurity
Let’s take...