SIS
Safety Instrumented System
Sicherheits-Notabschaltsystem
An SIS is an independent safety system that automatically brings an industrial facility into a safe state when a process reaches dangerous limits — such as overpressure or overheating. It is the last technical protection barrier for preventing damage to people, the environment and the plant. An attack on it is especially consequential.
History & facts. Safety instrumented systems are deliberately separate and redundantly designed so that they can intervene independently of the normal process control system (functional safety per IEC 61508/61511). They are the instance that prevents worse when everything else fails. The Triton/TRISIS malware in 2017 attacked such a system (Schneider Triconex) specifically for the first time — a breaking of a taboo, because a manipulated SIS can enable death or physical destruction.
Outlook & recommendation. Precisely because the SIS is the last line of protection, its integrity must be especially protected: consistent separation from the process control level, the strictest control of engineering access and the treatment of every change to the safety logic as a highly critical event. Since these systems are traditionally located with plant engineering and not with IT security, the interlocking of both worlds is decisive — a core concern of standards-compliant OT security.