System Requirements
IEC 62443-3-3:2013 is the control system requirements part. It belongs after the system under consideration, zones, conduits, and target security levels have been defined.
System, not component
IEC describes IEC 62443-3-3 as detailed technical control system requirements associated with the seven foundational requirements. The page is about a control system and its capability security levels, not a single embedded device, software package, corporate process, or service-provider capability.
IEC 62443-3-3 uses control system requirements and SL-C(control system). A product or component certificate may support the system file, but it does not replace the system architecture, configuration, and operating controls.
IEC 62443-2-1 is about the asset owner security programme for an IACS in operation. IEC 62443-3-3 is about detailed technical control system requirements and security levels.
IEC 62443-2-4 addresses service-provider processes for integration and maintenance. Those processes may help implement 3-3, but they do not prove the technical control system requirements on their own.
How it connects to IEC 62443-3-2
IEC 62443-3-3 depends on the system model created through IEC 62443-3-2. The 3-2 work defines the system under consideration, partitions it into zones and conduits, assesses risk, establishes SL-T, and documents security requirements. IEC 62443-3-3 then provides the system requirement structure used to express and evaluate the required capability.
Define
Define the system under consideration and the zones and conduits inside or around it.
Assess
Assess risk for each zone and conduit and establish SL-T for the relevant system boundary.
Specify
Use IEC 62443-3-3 to express control system requirements and SL-C(control system).
This sequence prevents a common error: selecting 3-3 requirements without knowing which zone, conduit, asset, threat environment, or target level they are meant to support.
Useful system evidence
System evidence usually needs more than product documents. It should explain the deployed or designed architecture and the responsibility split between the asset owner, integrator, maintenance provider, and product supplier.
- system boundary and asset list;
- zone and conduit model;
- communication paths and remote access paths;
- risk rationale and SL-T for each relevant zone or conduit;
- selected IEC 62443-3-3 requirements and SL-C(control system) claim;
- implemented technical and organisational controls;
- product and component capability evidence used by the design;
- operational procedures, monitoring, and maintenance responsibilities;
- validation evidence for the deployed design.
Deployed-state evidence
Configuration, network paths, remote access, accounts, monitoring, backups, and maintenance procedures need to reflect the system as it is built or approved.
Certification scope
A system assessment should state whether the certificate or report covers capability, application of capabilities, or a defined solution scope.