IEC Issued IEC 62443-4-2:2024 Cybersecurity for industrial control systems — Specific requirements for elevators and escalators International Standard
On October 18, 2024, the IEC/TC 65 Technical Committee of the International Electrotechnical Commission, together with the IEC/TC 21 Technical Committee, officially issued the international standard IEC 62443-4-2:2024 Cybersecurity for industrial control systems — Specific requirements for elevators and escalators, which will officially take effect on April 18, 2025. It is the world's first special international standard for cybersecurity in the field of elevators and escalators. The core contents of this standard include: First, clarify the scope of application of the standard, covering all elevators, escalators and moving walks equipped with network communication functions, remote monitoring functions, and intelligent control systems, applicable to the cybersecurity management of the whole life cycle of equipment design, manufacture, installation, operation and maintenance, and scrapping. Second, establish an elevator cybersecurity classification system. According to the elevator use scenario, safety risk level and functional importance, the elevator cybersecurity is divided into four security levels (SL1-SL4), and differentiated security protection requirements are formulated for different levels. Third, refine the cybersecurity requirements for the whole life cycle of elevators, and formulate comprehensive cybersecurity management specifications from five dimensions: security development life cycle, supply chain security, installation and deployment security, operation and maintenance security, and scrapping disposal security. Fourth, clarify the cybersecurity technical requirements for elevator control systems, and formulate mandatory technical standards for identity authentication, access control, data encryption, intrusion prevention, malicious code protection, and security audit for elevator main controllers, remote monitoring systems, human-machine interaction interfaces, and communication interfaces. Fifth, standardize the cybersecurity requirements for remote operation and maintenance of elevators, formulate special security protection standards for remote monitoring, remote debugging, and remote software update scenarios, and clarify the authority control, operation audit, emergency disposal, and data transmission encryption requirements for remote operations. Sixth, refine the requirements for elevator data security and privacy protection, clarify the security guidelines for the collection, storage, transmission, use and destruction of elevator operation data, maintenance data and personal information, and prohibit illegal collection, leakage and abuse of user personal information. Seventh, standardize the requirements for elevator cybersecurity testing and assessment, formulate the testing methods, risk assessment process and qualification criteria for elevator cybersecurity, and clarify the annual assessment and regular penetration testing requirements for elevator cybersecurity. Eighth, formulate the emergency disposal specification for elevator cybersecurity incidents, clarify the emergency response process, disposal measures, post-event recovery and traceability management requirements for cybersecurity incidents, and establish a hierarchical response mechanism for elevator cybersecurity incidents. After its release, this standard has been launched into the national standard conversion procedure by more than 100 countries and regions around the world such as the European Union, China, the United States and Japan, comprehensively unifying the cybersecurity protection technical requirements for smart elevators worldwide.