The Ministry of Industry and Information Technology (MIIT) has released the "Guidelines for Cybersecurity Protection of Industrial Control Systems"

freeFree Technical Resource

This content is free to read, suitable for basic learning and search traffic.

The Ministry of Industry and Information Technology (MIIT) has released the "Guidelines for Cybersecurity Protection of Industrial Control Systems"

In recent years, with the rapid development of information technology and the accelerated advancement of industrialization, the cybersecurity of industrial control systems in China has faced unprecedented challenges. Industrial control systems generally suffer from imperfect security protection measures and numerous vulnerabilities, making them vulnerable to threats such as hacker attacks and malware intrusions. Moreover, industrial control systems are often connected to the Internet, with unclear network boundaries, making them susceptible to external attacks and seriously affecting the stability of system operation.
As an important component of critical infrastructure, the stable operation of industrial control systems is of great significance for safeguarding national economic security and social stability. In order to adapt to the new industrialization development situation, improve the level of cybersecurity protection for China's industrial control systems, guide industrial enterprises in carrying out industrial control security protection work, and escort the high-quality development of new industrialization with high-level security, the Ministry of Industry and Information Technology has issued the "Guidelines for Cybersecurity Protection of Industrial Control Systems". The full text is as follows:
I. Security Management

(I) Asset Management
1. Comprehensively sort out typical industrial control systems such as Programmable Logic Controllers (PLC), Distributed Control Systems (DCS), Supervisory Control and Data Acquisition (SCADA), as well as related equipment, software, data, and other assets. Clarify the responsibility departments and individuals for asset management, establish an inventory of industrial control system assets, and update it in a timely manner according to changes in asset status. Regularly conduct asset verification of industrial control systems, including but not limited to system configuration, permission allocation, log auditing, virus scanning, data backup, and equipment operating status.
2. Establish and regularly update a list of important industrial control systems based on factors such as the importance and scale of the business they carry, as well as the degree of harm caused by cybersecurity incidents, and implement key protection measures. Key industrial hosts, network equipment, control equipment, etc., related to important industrial control systems, should be implemented with redundancy backup.
(II) Configuration Management
3. Strengthen account and password management, avoid using default passwords or weak passwords, and regularly update passwords. Follow the principle of minimum authorization, reasonably set account permissions, disable unnecessary system default accounts and administrator accounts, and promptly clean up expired accounts.
4. Establish a security configuration inventory for industrial control systems and a policy configuration inventory for security protection equipment. Regularly conduct audits of the configuration inventory, adjust configurations in a timely manner according to changes in security protection needs, and conduct strict security testing before implementing major configuration changes. Changes can only be implemented after passing the test.
(III) Supply chain security
5. In agreements signed with suppliers such as industrial control system manufacturers, cloud service providers, and security service providers, the security-related responsibilities and obligations that each party needs to fulfill should be clearly defined, including management scope, division of responsibilities, access authorization, privacy protection, code of conduct, and liability for breach of contract.
6. When using PLCs and other equipment included in the directory of network-critical devices in industrial control systems, only equipment that has been qualified through security certification by a qualified institution or meets the required standards through security testing should be used.
(IV) Publicity and Education
7. Regularly carry out publicity and education on laws, regulations, policies, and standards related to the cybersecurity of industrial control systems, to enhance the cybersecurity awareness of enterprise personnel. For industrial control system and network-related operation and maintenance personnel, regularly conduct professional industrial control security training and assessments.
II. Technical Protection

(I) Host and Terminal Security
8. Deploy antivirus software on hosts such as engineer stations, operator stations, and industrial database servers, regularly update virus databases and perform virus scans to prevent the spread of ransomware and other malicious software. For media with storage capabilities, perform virus and Trojan scans before connecting them to industrial hosts.
9. Hosts can adopt application software whitelist technology, allowing only the deployment and operation of application software authorized and security-assessed by the enterprise, and systematically implement upgrades for operating systems, databases, and other system software as well as important application software.
10. Remove or block unnecessary external device interfaces such as Universal Serial Bus (USB), optical drives, and wireless interfaces on industrial hosts, and close unnecessary network service ports. If external devices are indeed necessary, strict access control should be implemented.
11. Implement user identity authentication for accessing industrial hosts, industrial intelligent terminal devices (control devices, intelligent instruments, etc.), and network devices (industrial switches, industrial routers, etc.), and adopt two-factor authentication for accessing key hosts or terminals.
(II) Architecture and Boundary Security
12. Based on factors such as the characteristics of the hosted business, business scale, and the importance of affecting industrial production, implement zoning and domain management for industrial control networks composed of industrial Ethernet and industrial wireless networks, deploy industrial firewalls, gateways, and other devices to achieve horizontal isolation between domains. When the industrial control network is connected to the enterprise management network or the Internet, implement vertical protection between networks and conduct security audits for inter-network behaviors. Identity authentication should be performed when devices are connected to the industrial control network.
13. When using wireless communication technologies such as fifth-generation mobile communication technology (5G) and wireless local area network technology (Wi-Fi) to form a network, establish strict network access control policies, adopt identity authentication mechanisms for wireless access devices, regularly audit wireless access points, disable the broadcast of wireless access public information (SSID), and prevent unauthorized device access.
14. Strictly control remote access and prohibit industrial control systems from opening unnecessary high-risk general network services such as Hypertext Transfer Protocol (HTTP), File Transfer Protocol (FTP), Internet Telnet (Telnet), Remote Desktop Protocol (RDP), etc. to the Internet. For necessary network services, adopt technologies such as secure access proxy for user identity authentication and application authorization. During remote maintenance, use protocols such as Internet Protocol Security (IPsec) and Secure Sockets Layer (SSL) to construct secure network channels (such as Virtual Private Networks (VPN)), strictly limit access scope and authorization time, and carry out log retention and auditing.
15. The use of encryption protocols and algorithms in industrial control systems should comply with relevant laws and regulations. It is encouraged to prioritize the adoption of commercial cryptography to achieve encrypted network communication, device identity authentication, and secure data transmission.
(III) Cloud Security
16. When industrial cloud platforms are self-built by enterprises, security measures such as user identity authentication, access control, secure communication, and intrusion prevention should be employed to effectively prevent illegal operations and cyberattacks.
17. When industrial devices are connected to the cloud, strict identification management should be implemented for the devices. Two-way identity authentication should be adopted when devices are connected to the industrial cloud platform, and unidentified devices should be prohibited from accessing the platform. When business systems are migrated to the cloud, it is necessary to ensure the security isolation of different business system operating environments.
(IV) Application Security
18. User identity authentication should be required when accessing application services such as Manufacturing Execution Systems (MES), configuration software, and industrial databases. For critical application services, two-factor authentication should be adopted, and access scope and authorization time should be strictly limited.
19. Software related to industrial control systems independently developed by industrial enterprises should undergo security testing conducted by the enterprises themselves or third-party organizations. Only after passing the test can the software be launched for use.
(V) System Data Security
20. Regularly organize data generated by the operation of industrial control systems, conduct data classification and grading based on business practices, identify important and core data, and form a directory. Focusing on data collection, storage, use, processing, transmission, provision, and disclosure, use cryptographic technology, access control, disaster recovery backup, and other technologies to implement security protection for data.
21. For important and core data that are required by laws and administrative regulations to be stored within the country, they should be stored within the country. If it is necessary to provide such data to overseas entities, security assessments for data export should be conducted in accordance with laws and regulations.
III. Security Operations

((I) Monitoring and Early Warning

22. Deploy monitoring and auditing devices or platforms on industrial control networks, and promptly detect and alert system vulnerabilities, malicious software, network attacks, network intrusions, and other security risks without affecting the stable operation of the system.
23. At the boundary between industrial control networks and enterprise management networks or the Internet, threat trapping technologies such as industrial control system honeypots can be employed to capture network attack behaviors and enhance active defense capabilities.
(II) Operation Center
24. Enterprises with the necessary conditions can establish an industrial control system network security operation center, utilizing technologies such as Security Orchestration Automation and Response (SOAR) to achieve unified management and policy configuration of security devices, comprehensively monitor network security threats, and enhance the ability to centrally investigate potential risks and respond quickly to incidents.
(III) Emergency Response
25. Develop emergency response plans for industrial control security incidents, clarify reporting and handling procedures, conduct timely assessments and revisions based on actual situations, and regularly carry out emergency drills. In the event of an industrial control security incident, the emergency response plan should be immediately activated, emergency measures should be taken, and the security incident should be handled promptly and safely.
26. The access and operation logs of important equipment, platforms, and systems should be retained for at least six months, and regular backups of the logs should be made to facilitate post-incident traceability and evidence collection.
27. Regular backups and recovery tests should be conducted for important system applications and data to ensure that the industrial control system can resume normal operation within an acceptable time frame in case of emergency.
(IV) Security Assessment
28. Before the launch of newly built or upgraded industrial control systems and before connecting industrial control networks with enterprise management networks or the Internet, security risk assessments should be conducted.
29. For important industrial control systems, enterprises should conduct or entrust third-party professional institutions to conduct at least one industrial control security protection capability-related assessment annually.
(V) Vulnerability Management
30. Pay close attention to major industrial control system security vulnerabilities and their patch releases on platforms such as the Cybersecurity Threat and Vulnerability Information Sharing Platform of the Ministry of Industry and Information Technology, and take timely measures to upgrade. For those that cannot be upgraded in the short term, targeted security reinforcement should be carried out.
31. Regularly conduct vulnerability assessments on important industrial control systems. When major security vulnerabilities are discovered, patch upgrades or reinforcement measures should be implemented only after testing and verifying the patches or reinforcement measures.
IV. Implementation of Responsibilities

32. Industrial enterprises bear the primary responsibility for their own industrial control system security, establish industrial control security management systems, clarify responsible individuals and departments, and implement industrial control security protection responsibilities in accordance with the principle of "who operates is responsible, who supervises is responsible".
33. Strengthen enterprise resource support to ensure that security protection measures are planned, constructed, and used simultaneously with industrial control systems.

Put this resource to use in a real project?

Go to the Tool Center for message parsing, CRC verification and device debugging, or submit your requirements for selection and integration advice.

Engineer Membership

Turn this article into actionable debugging resources

After activation, you can use advanced message parsing, resource pack downloads, code examples, engineering cases and priority technical support, suitable for real project delivery.

Unlimited Advanced Tools
Resource & Code Packs
Complete Engineering Case Library
Priority Technical Support

Leave a Reply

Your email address will not be published. Required fields are marked *.