Skip to content

Evidence request lists

IEC 62351 - Power Systems Communication Security

Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Access Control

IEC62351-8
Role-Based Access Control

Apply role-based access control to subjects accessing power system devices with verifiable identities.

Artefacts an auditor will ask for
  • Role definitions
  • Assignment matrix
  • Access review records
Where this commonly fails
  • Shared accounts persist
  • Roles not reviewed quarterly

Application Security

IEC62351-4
MMS and IEC 61850 Application Security

Apply end-to-end authentication and optional encryption to MMS associations used by IEC 61850.

Artefacts an auditor will ask for
  • MMS handshake logs
  • A-Profile configuration
  • Test report against test cases
Where this commonly fails
  • Authentication off in production
  • No interop test record

Architecture

IEC62351-10
Security Architecture

Apply defence in depth across power system zones with documented architecture and trust boundaries.

Artefacts an auditor will ask for
  • Network diagrams
  • Zone and conduit document
  • Threat model
Where this commonly fails
  • Flat OT network
  • No conduit inventory

Communications Security

IEC62351-3
TLS for TCP/IP Profiles

Apply TLS to TCP/IP based protocols used in power systems including authentication, integrity, and confidentiality.

Artefacts an auditor will ask for
  • TLS handshake captures
  • Approved cipher list
  • Certificate inventory
Where this commonly fails
  • Weak ciphers still allowed
  • Self-signed certificates without controls

Conformance

IEC62351-100
Conformance Testing

Demonstrate conformance to applicable IEC 62351 profiles through test procedures and documented results.

Artefacts an auditor will ask for
  • Test procedures
  • Lab reports
  • Vendor attestations
Where this commonly fails
  • No vendor conformance report
  • In-house tests not aligned to IEC procedures

Cryptography

IEC62351-9
Cybersecurity Key Management

Manage cryptographic keys and certificates across their lifecycle for power system applications.

Artefacts an auditor will ask for
  • CP/CPS document
  • Key ceremony logs
  • Revocation evidence
Where this commonly fails
  • No CRL/OCSP available offline
  • Manual key handling without dual control

Data Security

IEC62351-11
XML File Security

Protect XML configuration files such as SCL with signatures and optional encryption.

Artefacts an auditor will ask for
  • Signed SCL examples
  • Verification tooling
  • Storage controls
Where this commonly fails
  • SCL files exchanged unsigned
  • No verification before import

Governance

IEC62351-13
Guidelines on Security Topics

Apply guideline topics on security for power system operations including procurement and lifecycle.

Artefacts an auditor will ask for
  • Procurement security requirements
  • Supplier attestations
  • Audit records
Where this commonly fails
  • No security clauses in purchase orders
  • Supplier attestations missing

Incident Response

IEC62351-IR
Incident Response for Substations

Plan and exercise incident response for substation cyber events including forensic data preservation.

Artefacts an auditor will ask for
  • Runbooks for protocol misuse
  • Tabletop minutes
  • Forensic acquisition procedure
Where this commonly fails
  • No OT-specific runbooks
  • Forensic data overwritten

Inter-Control Centre

IEC62351-ICCP
ICCP/TASE.2 Secure Bilateral

Secure ICCP/TASE.2 bilateral exchanges between control centres including authentication and authorised data sets.

Artefacts an auditor will ask for
  • Bilateral agreement table
  • TLS configuration
  • Change records
Where this commonly fails
  • Outdated bilateral tables
  • Unencrypted ICCP across WAN

Logging

IEC62351-14
Cybersecurity Event Logging

Generate, transport, and retain cybersecurity event logs across power system devices and systems.

Artefacts an auditor will ask for
  • Event log examples
  • Retention policy
  • Time sync evidence
Where this commonly fails
  • Inconsistent timestamps
  • No central aggregation

Monitoring

IEC62351-MON
Security Monitoring of Substation Networks

Continuously monitor substation networks for anomalies, unauthorised devices, and protocol misuse.

Artefacts an auditor will ask for
  • IDS rule set
  • Anomaly reports
  • Investigation records
Where this commonly fails
  • Passive monitoring absent
  • Detection rules not tuned to OT protocols

Network Security

IEC62351-SEG
Segmentation of Process and Station Buses

Segment process bus, station bus, and corporate networks with enforced data flow controls.

Artefacts an auditor will ask for
  • VLAN/firewall rules
  • Data flow diagrams
  • Audit of east-west traffic
Where this commonly fails
  • Flat layer 2 across bays
  • Engineering laptops dual-homed

Operations

IEC62351-7
Network and System Management

Define data object models for monitoring security health of power system communications.

Artefacts an auditor will ask for
  • SNMP/IEC 61850 NSM mapping
  • SIEM ingestion records
  • Alert runbooks
Where this commonly fails
  • NSM points not monitored
  • Alerts not triaged

PKI

IEC62351-CERT
Certificate Lifecycle for Substations

Issue, renew, and revoke device certificates supporting substation devices with offline capability.

Artefacts an auditor will ask for
  • Issuance logs
  • Renewal calendar
  • Revocation drills
Where this commonly fails
  • Long-lived certificates
  • No offline revocation path

Parts 1-2: Introduction and Glossary

62351-1
Introduction

Background on security for power system control operations and introductory information on the IEC 62351 series

Artefacts an auditor will ask for
  • Protocol security profile
  • Key management procedure
  • RBAC matrix
  • Logging configuration
Where this commonly fails
  • Legacy protocols unsecured
  • Inconsistent key lifecycle
  • Sparse OT logging
62351-2
Glossary of terms

Definitions of terms and acronyms used in the IEC 62351 standards series

Artefacts an auditor will ask for
  • Protocol security profile
  • Key management procedure
  • RBAC matrix
  • Logging configuration
Where this commonly fails
  • Legacy protocols unsecured
  • Inconsistent key lifecycle
  • Sparse OT logging

Parts 10-11: Architecture and XML Security

62351-10
Security architecture guidelines

Explains security architectures of the entire IT infrastructure with focus on special security requirements in power generation

Artefacts an auditor will ask for
  • Protocol security profile
  • Key management procedure
  • RBAC matrix
  • Logging configuration
Where this commonly fails
  • Legacy protocols unsecured
  • Inconsistent key lifecycle
  • Sparse OT logging
62351-11
Security for XML documents

Security for XML files through embedding the original XML content into an XML container with digital signatures

Artefacts an auditor will ask for
  • Protocol security profile
  • Key management procedure
  • RBAC matrix
  • Logging configuration
Where this commonly fails
  • Legacy protocols unsecured
  • Inconsistent key lifecycle
  • Sparse OT logging

Parts 12-14: DER, Resilience, and Monitoring

62351-12
Resilience and security recommendations for DER

Cybersecurity recommendations and strategies for improving resilience of power systems with interconnected Distributed Energy Resources

Artefacts an auditor will ask for
  • Protocol security profile
  • Key management procedure
  • RBAC matrix
  • Logging configuration
Where this commonly fails
  • Legacy protocols unsecured
  • Inconsistent key lifecycle
  • Sparse OT logging
62351-13
Cyber-physical generation and storage resilience

Resilience requirements for dispersed cyber-physical generation and storage devices in power systems

Artefacts an auditor will ask for
  • Protocol security profile
  • Key management procedure
  • RBAC matrix
  • Logging configuration
Where this commonly fails
  • Legacy protocols unsecured
  • Inconsistent key lifecycle
  • Sparse OT logging
62351-14
Cyber security event logging

Standardized generation and monitoring of cyber security event logs in power systems

Artefacts an auditor will ask for
  • Protocol security profile
  • Key management procedure
  • RBAC matrix
  • Logging configuration
Where this commonly fails
  • Legacy protocols unsecured
  • Inconsistent key lifecycle
  • Sparse OT logging

Parts 3-4: TCP/IP and MMS Security Profiles

62351-3
Profiles including TCP/IP

Data and communication security for profiles including TCP/IP used in power system communications

Artefacts an auditor will ask for
  • Protocol security profile
  • Key management procedure
  • RBAC matrix
  • Logging configuration
Where this commonly fails
  • Legacy protocols unsecured
  • Inconsistent key lifecycle
  • Sparse OT logging
62351-4
Profiles including MMS and similar payloads

Data and communication security for profiles including MMS (Manufacturing Message Specification) and similar payloads

Artefacts an auditor will ask for
  • Protocol security profile
  • Key management procedure
  • RBAC matrix
  • Logging configuration
Where this commonly fails
  • Legacy protocols unsecured
  • Inconsistent key lifecycle
  • Sparse OT logging

Parts 5-6: Protocol-Specific Security

62351-5
Security for IEC 60870-5 and derivatives

Data and communication security for IEC 60870-5 protocols and derivatives including DNP 3.0

Artefacts an auditor will ask for
  • Protocol security profile
  • Key management procedure
  • RBAC matrix
  • Logging configuration
Where this commonly fails
  • Legacy protocols unsecured
  • Inconsistent key lifecycle
  • Sparse OT logging
62351-6
Security for IEC 61850 profiles

Security for IEC 61850 protocol profiles using VLAN marks and X.509 signatures on GOOSE and SMV telegrams

Artefacts an auditor will ask for
  • Protocol security profile
  • Key management procedure
  • RBAC matrix
  • Logging configuration
Where this commonly fails
  • Legacy protocols unsecured
  • Inconsistent key lifecycle
  • Sparse OT logging

Parts 7-9: Network Management, Access Control, and Key Management

62351-7
Network and system management (NSM)

Security through network and system management tools for monitoring power grid infrastructure using SNMP protocol

Artefacts an auditor will ask for
  • Protocol security profile
  • Key management procedure
  • RBAC matrix
  • Logging configuration
Where this commonly fails
  • Legacy protocols unsecured
  • Inconsistent key lifecycle
  • Sparse OT logging
62351-8
Role-based access control (RBAC)

Access control of users and automated agents to data objects in power systems based on roles

Artefacts an auditor will ask for
  • Protocol security profile
  • Key management procedure
  • RBAC matrix
  • Logging configuration
Where this commonly fails
  • Legacy protocols unsecured
  • Inconsistent key lifecycle
  • Sparse OT logging
62351-9
Cyber security key management

Correct and safe usage of security-critical parameters including encryption keys and lifecycle of cryptographic information

Artefacts an auditor will ask for
  • Protocol security profile
  • Key management procedure
  • RBAC matrix
  • Logging configuration
Where this commonly fails
  • Legacy protocols unsecured
  • Inconsistent key lifecycle
  • Sparse OT logging

Protocol Security

IEC62351-5
IEC 60870-5 and DNP3 Secure Authentication

Apply secure authentication for IEC 60870-5 and DNP3 to protect critical operations on serial and networked links.

Artefacts an auditor will ask for
  • Outstation/master config
  • Key update logs
  • Aggressive mode disabled evidence
Where this commonly fails
  • Pre-shared keys not rotated
  • Aggressive mode left enabled without justification

Resilience

IEC62351-12
Resilience for DER and Substation Automation

Apply resilience recommendations for distributed energy resources and substation automation including failover and integrity checks.

Artefacts an auditor will ask for
  • Failover test results
  • DER onboarding security checklist
  • Integrity monitoring records
Where this commonly fails
  • DER endpoints unauthenticated
  • No failover tested

Substation Security

IEC62351-6
IEC 61850 GOOSE and SV Security

Provide authentication for GOOSE and Sampled Values multicast messages used in substations.

Artefacts an auditor will ask for
  • VLAN segmentation map
  • MAC layer auth configuration
  • Latency test results
Where this commonly fails
  • Performance budget exceeded
  • No segmentation for multicast traffic

Supplier

IEC62351-SUP
Supplier Security Requirements

Require suppliers to meet documented IEC 62351 capabilities and provide evidence at delivery.

Artefacts an auditor will ask for
  • Security requirements clauses
  • Factory acceptance test reports
  • Site acceptance test reports
Where this commonly fails
  • FAT/SAT lacks security tests
  • No traceability to clauses

Vulnerability

IEC62351-PATCH
Patch and Vulnerability Management for OT

Track and apply security patches for substation devices using risk-based scheduling and rollback plans.

Artefacts an auditor will ask for
  • CVE register
  • Patch deployment plan
  • Rollback evidence
Where this commonly fails
  • No risk-based prioritisation
  • Patches deferred without compensating controls
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the IEC 62351 - Power Systems Communication Security framework page.