Skip to main content
MSMUG
ABOUT US
MEMBERSHIP
EVENTS
GENERAL FORUM
  
MSMUG > Team Discussion > Content Collection for ISA 99.06  
Go Search

Team Discussion

Modify settings and columns
Use the Team Discussion list to hold newsgroup-style discussions on topics relevant to your team.
  
View: 
Post
Started: 5/22/2009 8:19 AM
Picture Placeholder: Florian Ott
Florian Ott
Content Collection for ISA 99.06
Here we waht to collect and discuss what should be in the ISA 99.06 document.
 
In our Sharepoint, there is a document, created by Bob Mick and Donovan Tindill, with a example "table of contants" and some ideas what should be in the document.
 
 
I also had some ideas, I send them to the mailinglist and now post them here, too.
 
Please write your comments and ideas.
Posted: 5/22/2009 8:21 AM
Picture Placeholder: Florian Ott
Florian Ott

I think the whole topic "Patchmanagement/Patchtesting" splits in 4 subtopics:

 

1. General issues (thing who addresses everyone)

2. Issues for the create of a patch

3. Issues for SCADA/Process Control vendors

4. Issus for SCADA/Process Control customers, plant owners or plant admins

 

 to 1.: - the patches must be tested

        - how a test environment should look like (but these could also be different for vendor and customer)

        - ....

 

to 2.: - addresses e.g. Microsoft, Networkmanagment vendors, Antivirus vendors... and SCADA/Process Control vendors, if they have patches

        - how to inform the customer about a new patch, a consistent format would be good

        - active or passive information

        - how fast, after a bug was found a patch must be released

        - how could patch creators help SCADA/Process Control vendors, to get patches earlier

        - .....

 

to 3.: - vendors should perform compatibility test with patches for 3rd party they use or allow

        - how fast, after a patch has released, the vendor must allocate information

        - a consistent form for the information from all vendors

        - a consistent wording from all vendors

        - .....

 

to 4.: - plant owners should perform compatibility test with patches

        - a patchmanagement and patch enrollment strategy

        - security strategies, the have some time for patching, and could wait a little bit

        - ......