System Requirements

IEC 62443-3-3:2013 is the control system requirements part. It belongs after the system under consideration, zones, conduits, and target security levels have been defined.

System, not component

IEC describes IEC 62443-3-3 as detailed technical control system requirements associated with the seven foundational requirements. The page is about a control system and its capability security levels, not a single embedded device, software package, corporate process, or service-provider capability.

How it connects to IEC 62443-3-2

IEC 62443-3-3 depends on the system model created through IEC 62443-3-2. The 3-2 work defines the system under consideration, partitions it into zones and conduits, assesses risk, establishes SL-T, and documents security requirements. IEC 62443-3-3 then provides the system requirement structure used to express and evaluate the required capability.

Define

Define the system under consideration and the zones and conduits inside or around it.

Assess

Assess risk for each zone and conduit and establish SL-T for the relevant system boundary.

Specify

Use IEC 62443-3-3 to express control system requirements and SL-C(control system).

This sequence prevents a common error: selecting 3-3 requirements without knowing which zone, conduit, asset, threat environment, or target level they are meant to support.

Useful system evidence

System evidence usually needs more than product documents. It should explain the deployed or designed architecture and the responsibility split between the asset owner, integrator, maintenance provider, and product supplier.

  • system boundary and asset list;
  • zone and conduit model;
  • communication paths and remote access paths;
  • risk rationale and SL-T for each relevant zone or conduit;
  • selected IEC 62443-3-3 requirements and SL-C(control system) claim;
  • implemented technical and organisational controls;
  • product and component capability evidence used by the design;
  • operational procedures, monitoring, and maintenance responsibilities;
  • validation evidence for the deployed design.

Deployed-state evidence

Configuration, network paths, remote access, accounts, monitoring, backups, and maintenance procedures need to reflect the system as it is built or approved.

Certification scope

A system assessment should state whether the certificate or report covers capability, application of capabilities, or a defined solution scope.

Sources