Section 5.4 establishes communication port access and protocol security requirements for IEDs. Per public IEEE 1686 abstract + vendor capability statements (full IEEE text NOT reproduced): communication port access control + port enable/disable + role-based permissions per port (5.4); encrypted remote access (5.4.1) including TLS for HTTPS + SSH + secure variants of substation protocols; cryptographic algorithm selection + key management + lifecycle. Substation protocol security: IEC 61850 (Substation Configuration Language SCL + GOOSE + Sampled Values SV + MMS Manufacturing Message Specification) + IEC 61850-90-5 Synchrophasors + IEC 62351 protocol security (IEC 62351-3 TLS + IEC 62351-4 application layer + IEC 62351-5 IEC 60870-5 secure + IEC 62351-6 IEC 61850 secure + IEC 62351-7 Network management + IEC 62351-8 Role-Based Access Control + IEC 62351-9 Key Management + IEC 62351-100 Conformance); DNP3 + DNP3 SAv5 (Secure Authentication version 5) per IEEE 1815 + IEEE 1815.1; Modbus + Modbus Security; IEC 60870-5-101/104 + IEC 62351-5. Ports and services management: disable unused services (Telnet + FTP + HTTP + SNMP v1/v2 + insecure) + enable secure variants (SSH + SFTP + HTTPS + SNMPv3 with authPriv) + port scan + baseline. Coordinates with IEC 62443-3-3 SR 4.1-4.3 (Data Confidentiality) + SR 5.1-5.4 (Restricted Data Flow Zones and Conduits) + IEC 62351 + DNP3 SAv5 + NERC CIP-005 + NIST SP 800-53 SC family + NIST SP 800-82 ICS-specific.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.