IEC 62351 - Power Systems Communication Security
Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Access Control
Apply role-based access control to subjects accessing power system devices with verifiable identities.
- Role definitions
- Assignment matrix
- Access review records
- Shared accounts persist
- Roles not reviewed quarterly
Application Security
Apply end-to-end authentication and optional encryption to MMS associations used by IEC 61850.
- MMS handshake logs
- A-Profile configuration
- Test report against test cases
- Authentication off in production
- No interop test record
Architecture
Apply defence in depth across power system zones with documented architecture and trust boundaries.
- Network diagrams
- Zone and conduit document
- Threat model
- Flat OT network
- No conduit inventory
Communications Security
Apply TLS to TCP/IP based protocols used in power systems including authentication, integrity, and confidentiality.
- TLS handshake captures
- Approved cipher list
- Certificate inventory
- Weak ciphers still allowed
- Self-signed certificates without controls
Conformance
Demonstrate conformance to applicable IEC 62351 profiles through test procedures and documented results.
- Test procedures
- Lab reports
- Vendor attestations
- No vendor conformance report
- In-house tests not aligned to IEC procedures
Cryptography
Manage cryptographic keys and certificates across their lifecycle for power system applications.
- CP/CPS document
- Key ceremony logs
- Revocation evidence
- No CRL/OCSP available offline
- Manual key handling without dual control
Data Security
Protect XML configuration files such as SCL with signatures and optional encryption.
- Signed SCL examples
- Verification tooling
- Storage controls
- SCL files exchanged unsigned
- No verification before import
Governance
Apply guideline topics on security for power system operations including procurement and lifecycle.
- Procurement security requirements
- Supplier attestations
- Audit records
- No security clauses in purchase orders
- Supplier attestations missing
Incident Response
Plan and exercise incident response for substation cyber events including forensic data preservation.
- Runbooks for protocol misuse
- Tabletop minutes
- Forensic acquisition procedure
- No OT-specific runbooks
- Forensic data overwritten
Inter-Control Centre
Secure ICCP/TASE.2 bilateral exchanges between control centres including authentication and authorised data sets.
- Bilateral agreement table
- TLS configuration
- Change records
- Outdated bilateral tables
- Unencrypted ICCP across WAN
Logging
Generate, transport, and retain cybersecurity event logs across power system devices and systems.
- Event log examples
- Retention policy
- Time sync evidence
- Inconsistent timestamps
- No central aggregation
Monitoring
Continuously monitor substation networks for anomalies, unauthorised devices, and protocol misuse.
- IDS rule set
- Anomaly reports
- Investigation records
- Passive monitoring absent
- Detection rules not tuned to OT protocols
Network Security
Segment process bus, station bus, and corporate networks with enforced data flow controls.
- VLAN/firewall rules
- Data flow diagrams
- Audit of east-west traffic
- Flat layer 2 across bays
- Engineering laptops dual-homed
Operations
Define data object models for monitoring security health of power system communications.
- SNMP/IEC 61850 NSM mapping
- SIEM ingestion records
- Alert runbooks
- NSM points not monitored
- Alerts not triaged
PKI
Issue, renew, and revoke device certificates supporting substation devices with offline capability.
- Issuance logs
- Renewal calendar
- Revocation drills
- Long-lived certificates
- No offline revocation path
Parts 1-2: Introduction and Glossary
Background on security for power system control operations and introductory information on the IEC 62351 series
- Protocol security profile
- Key management procedure
- RBAC matrix
- Logging configuration
- Legacy protocols unsecured
- Inconsistent key lifecycle
- Sparse OT logging
Definitions of terms and acronyms used in the IEC 62351 standards series
- Protocol security profile
- Key management procedure
- RBAC matrix
- Logging configuration
- Legacy protocols unsecured
- Inconsistent key lifecycle
- Sparse OT logging
Parts 10-11: Architecture and XML Security
Explains security architectures of the entire IT infrastructure with focus on special security requirements in power generation
- Protocol security profile
- Key management procedure
- RBAC matrix
- Logging configuration
- Legacy protocols unsecured
- Inconsistent key lifecycle
- Sparse OT logging
Security for XML files through embedding the original XML content into an XML container with digital signatures
- Protocol security profile
- Key management procedure
- RBAC matrix
- Logging configuration
- Legacy protocols unsecured
- Inconsistent key lifecycle
- Sparse OT logging
Parts 12-14: DER, Resilience, and Monitoring
Cybersecurity recommendations and strategies for improving resilience of power systems with interconnected Distributed Energy Resources
- Protocol security profile
- Key management procedure
- RBAC matrix
- Logging configuration
- Legacy protocols unsecured
- Inconsistent key lifecycle
- Sparse OT logging
Resilience requirements for dispersed cyber-physical generation and storage devices in power systems
- Protocol security profile
- Key management procedure
- RBAC matrix
- Logging configuration
- Legacy protocols unsecured
- Inconsistent key lifecycle
- Sparse OT logging
Standardized generation and monitoring of cyber security event logs in power systems
- Protocol security profile
- Key management procedure
- RBAC matrix
- Logging configuration
- Legacy protocols unsecured
- Inconsistent key lifecycle
- Sparse OT logging
Parts 3-4: TCP/IP and MMS Security Profiles
Data and communication security for profiles including TCP/IP used in power system communications
- Protocol security profile
- Key management procedure
- RBAC matrix
- Logging configuration
- Legacy protocols unsecured
- Inconsistent key lifecycle
- Sparse OT logging
Data and communication security for profiles including MMS (Manufacturing Message Specification) and similar payloads
- Protocol security profile
- Key management procedure
- RBAC matrix
- Logging configuration
- Legacy protocols unsecured
- Inconsistent key lifecycle
- Sparse OT logging
Parts 5-6: Protocol-Specific Security
Data and communication security for IEC 60870-5 protocols and derivatives including DNP 3.0
- Protocol security profile
- Key management procedure
- RBAC matrix
- Logging configuration
- Legacy protocols unsecured
- Inconsistent key lifecycle
- Sparse OT logging
Security for IEC 61850 protocol profiles using VLAN marks and X.509 signatures on GOOSE and SMV telegrams
- Protocol security profile
- Key management procedure
- RBAC matrix
- Logging configuration
- Legacy protocols unsecured
- Inconsistent key lifecycle
- Sparse OT logging
Parts 7-9: Network Management, Access Control, and Key Management
Security through network and system management tools for monitoring power grid infrastructure using SNMP protocol
- Protocol security profile
- Key management procedure
- RBAC matrix
- Logging configuration
- Legacy protocols unsecured
- Inconsistent key lifecycle
- Sparse OT logging
Access control of users and automated agents to data objects in power systems based on roles
- Protocol security profile
- Key management procedure
- RBAC matrix
- Logging configuration
- Legacy protocols unsecured
- Inconsistent key lifecycle
- Sparse OT logging
Correct and safe usage of security-critical parameters including encryption keys and lifecycle of cryptographic information
- Protocol security profile
- Key management procedure
- RBAC matrix
- Logging configuration
- Legacy protocols unsecured
- Inconsistent key lifecycle
- Sparse OT logging
Protocol Security
Apply secure authentication for IEC 60870-5 and DNP3 to protect critical operations on serial and networked links.
- Outstation/master config
- Key update logs
- Aggressive mode disabled evidence
- Pre-shared keys not rotated
- Aggressive mode left enabled without justification
Resilience
Apply resilience recommendations for distributed energy resources and substation automation including failover and integrity checks.
- Failover test results
- DER onboarding security checklist
- Integrity monitoring records
- DER endpoints unauthenticated
- No failover tested
Substation Security
Provide authentication for GOOSE and Sampled Values multicast messages used in substations.
- VLAN segmentation map
- MAC layer auth configuration
- Latency test results
- Performance budget exceeded
- No segmentation for multicast traffic
Supplier
Require suppliers to meet documented IEC 62351 capabilities and provide evidence at delivery.
- Security requirements clauses
- Factory acceptance test reports
- Site acceptance test reports
- FAT/SAT lacks security tests
- No traceability to clauses
Vulnerability
Track and apply security patches for substation devices using risk-based scheduling and rollback plans.
- CVE register
- Patch deployment plan
- Rollback evidence
- No risk-based prioritisation
- Patches deferred without compensating controls
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the IEC 62351 - Power Systems Communication Security framework page.