Bibliography

ANSI/ISA-51.1-1979 (R1993) “Process Instrumentation Terminology.”

ANSI/ISA-75.05.01-2000 (R2005) “Control Valve Terminology.”

ANSI/ISA-84.00.01-2004 (IEC 61511 Mod) “Functional Safety: Safety Instrumented Systems for the Process Industry Sector.”

ANSI/ISA-88.01-2010 (IEC 62264-1 Mod) “Batch Control Part 1: Models and Terminology.”

ANSI/ISA-95.00.01-2010 “Enterprise-Control System Integration, Part 1: Models and Terminology.”

ANSI/ISA-99.00.01-2007 “Security for Industrial Automation and Control Systems, Part 1: Terminology, Concepts and Models.”

ANSI/ISA-99.02.01-2009 “Security for Industrial Automation and Control Systems: Establishing an Industrial Automation and Control Systems Security Program.”

ANSI/ISA-TR99.00.01-2007 “Security for Industrial Automation and Control Systems, Technical Report 1: Security Technologies for Industrial Automation and Control Systems.”

Bailey, D. and Wright, E. Practical SCADA for Industry. Milpitas (CA): IDC Technologies, 2003.

Boyer, S. SCADA Supervisory Control and Data Acquisition, 2nd Edition. Research Triangle Park: ISA, 1999.

Carnegie Mellon Software Engineering Institute, Capability Maturity Model Integration (CMMI) for Software Engineering, v1.1. Pittsburgh: Carnegie Mellon University, 2002.

Committee on National Security Systems (CNSS) CNSS Instruction No. 4009, “National Information Assurance (IA) Glossary.” Washington, DC: CNSS, April 2010.

Erickson, K. and Hedrick, J. Plant Wide Process Control. Hoboken: John Wiley & Sons, 1999.

Falco, Joe, et al. IT Security for Industrial Control Systems. NIST IR 6859, 2003 at http://www.nist.gov/customcf/get_pdf.cfm?pub_id=821684.

Federal Information Processing Standards (FIPS) PUB 140-2 Security Requirements for Cryptographic Modules “Section 2, Glossary of Terms and Acronyms.” Washington, DC: U.S. National Institute of Standards and Technology, 2001.

FIPS PUB 199 Standards for Security Categorization of Federal Information and Information Systems. Washington, DC: U.S. National Institute of Standards and Technology, 2004.

FIPS PUB 200 Minimum Security Requirements for Federal Information and Information Systems. Washington, DC: U.S. National Institute of Standards and Technology, 2006.

IEC/PAS 62409 “Real-time Ethernet for Plant Automation, ed 1.0” (2005).

IEC/PAS 62410 “Real-time Ethernet SERCOS III, ed. 1.0” (2005).

International Electrotechnical Commission (IEC) Glossary at http://std.iec.ch/glossary. Geneva: IEC.

International Society of Automation The Automation, Systems, and Instrumentation Dictionary, 4th Edition. Research Triangle Park: ISA, 2003.

ISA-dTR62443-1-2, “Security for Industrial Automation and Control Systems - Master Glossary of Terms and Abbreviations,” 2011.

ISA-d99.02.02 “Security for Industrial Automation and Control Systems: Operating an Industrial Automation and Control System Security Program.”

ISA-d99.03.01, “Security for industrial automation and control systems: Target security levels.”

ISA-d99.03.02, “Security for industrial automation and control systems: System security compliance.”

ISA-d99.03.03, “Security for industrial automation and control systems: Technical security requirements for industrial automation and control systems.”

ISO/IEC 10746-1:1998 “Information technology – Open Distributed Processing – Reference model: Overview.”

ISO/IEC 15408-1:2009 “Information technology – Security techniques – Evaluation criteria for IT security – Part 1: Introduction and general model.”

ISO/IEC 15408-2:2008 “Information technology – Security techniques – Evaluation criteria for IT security – Part 2: Security functional requirements.”

ISO/IEC 15408-3:2008 “Information technology – Security techniques – Evaluation criteria for IT security – Part 3: Security assurance requirements.”

ISO/IEC 17799:2005 “Information technology – Security techniques – Code of practice for information security management.”

ISO/IEC 27001:2005 “Information technology – Security techniques – Information security management systems – Requirements.”

ISO/IEC 7498-2:1989 “Information processing systems – Open System Interconnection – Basic reference Model – Part 2: Security Architecture.”

NIST Process Control Security Requirements Forum (PCSRF), Industrial Control System-System Protection Profile (ICS-SPP), Version 1.0, Washington, DC: National Institute of Science and Technology, 2004.

NIST SP 800-18 Revision 1 “Guide for Developing Security Plans for Federal Information Systems,” Washington, DC: National Institute of Science and Technology, 2006.

NIST SP 800-28 “Guidelines on Active Content and Mobile Code,” Version 2, Washington, DC: National Institute of Science and Technology, 2008.

NIST SP 800-30 “Risk Management Guide for Information Technology Systems” Washington, DC: National Institute of Science and Technology, 2002.

NIST SP 800-30 Revision 1, “DRAFT Guide for Conducting Risk Assessments, “Washington, DC: National Institute of Science and Technology, 2011.

NIST SP 800-34 “Contingency Planning Guide for Information Technology Systems, Revision 1,” Washington, DC: National Institute of Science and Technology, 2010.

NIST SP 800-37 “Guide for Applying the Risk Management Framework to Federal Information Systems, Revision 1,” Washington, DC: National Institute of Science and Technology, 2010.

NIST SP 800-47 “Security Guide for Interconnecting Information Technology Systems,” Washington, DC: National Institute of Science and Technology, 2002.

NIST SP 800-53 Revision 3 “Recommended Security Controls for Federal Information Systems.” Washington, DC: National Institute of Science and Technology, 2010.

NIST SP 800-61 “Computer Security Incident Handling Guide, Revision 2(Draft)” Washington, DC: National Institute of Science and Technology, 2012.

NIST SP 800-82 “Guide to Industrial Control Systems (ICS) Security,” Washington, DC: National Institute of Science and Technology, 2011.

NIST SP 800-137 “Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations,” Washington, DC: National Institute of Science and Technology, 2011.