IEEE 1686
IEEE 1686 Section 5.5-5.8 - Firmware + Config + Time + Data

IEEE 1686 Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest: IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability

Sections 5.5 + 5.6 + 5.7 + 5.8 establish firmware + configuration + time + data protection capabilities required of IEDs. Per public IEEE 1686 abstract + vendor capability statements (full IEEE text NOT reproduced): Section 5.5 Firmware Quality and Update Control - signed firmware + integrity verification + secure boot where feasible + rollback protection + atomic update + emergency reverse; vendor patch lifecycle commitment + ICS-CERT advisory tracking; coordinated with security patch management for OT (test on shadow + risk-based + emergency patch procedure + maintenance windows + dry-dock equivalent for substations). Section 5.6 Configuration Software Security - vendor configuration software (e.g. AcSELerator + DIGSI + PCM600 + IEC 61850 IED Configuration Tool ICT) + secure communications + RBAC + audit; configuration management including baseline + change control + approved configurations + signed configuration files + rollback. Section 5.7 Time Synchronisation - accurate time source (NTP + GPS + IRIG-B + IEEE 1588 PTPv2 Precision Time Protocol Power Profile + IEC 61850-9-3) + time stamp accuracy for audit trail forensic correlation + relay protection coordination. Section 5.8 Encryption of Sensitive Data at Rest - encrypted storage for configuration + credentials + cryptographic keys + sensitive operational data; key management + lifecycle + rotation. Beyond Section 5.5-5.8: malware prevention for OT (anti-malware where compatible + whitelisting for safety-critical + USB controls); system security hardening including secure baseline + STIG/CIS adaptation + unused services disabled; vulnerability assessment + CVE tracking + ICS-CERT advisories + penetration testing + USM Universal Substation Manufacturer + JATC Joint Automation Test Coordination. Coordinates with IEC 62443-3-3 SR 3.1-3.9 (System Integrity) + IEC 62443-4-1 (Secure Product Development Lifecycle) + IEC 62443-4-2 CR 3.x + NERC CIP-007 + NERC CIP-010 (Configuration Change Management and Vulnerability Assessments) + NIST SP 800-53 SI + CM families.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.