Industrial Cybersecurity Standards

IEC 62443 is a standards series for industrial automation and control systems. It is best read by role and scope: organisation, service provider, system, secure development process, or component.

Industrial control system standards

The series addresses industrial automation and control systems across their lifecycle. It is not only a device standard and not only a network-security baseline. The same site may need asset-owner programme evidence, service-provider evidence, system design evidence, and supplier product evidence.

Roles and scope

A common mistake is to say a product, service, or plant is simply IEC 62443 compliant. The useful claim names the role, the part of the series, the edition, and the scope being assessed.

Asset owner

Owns the operating environment, policies, risk decisions, and many site-level controls.

System designer

Defines the system boundary, zones, conduits, requirements, and target security levels.

Product supplier

Provides secure development evidence and component capability evidence for supplied products.

Service provider

Shows capability for integration, maintenance, and related services within a defined profile.

Main parts used in practice

The pages in this module use the public series structure rather than copying a private standard. The cards below give the reader the basic map before moving into deeper pages.

IEC 62443-2-1

Asset-owner security programme for an IACS in operation.

IEC 62443-2-4

Service-provider capabilities for integration and maintenance.

IEC 62443-3-2

System risk assessment, zones, conduits, and target security levels.

IEC 62443-3-3

System security requirements and security levels.

IEC 62443-4-1

Secure product development lifecycle for product suppliers.

IEC 62443-4-2

Technical security capability requirements for IACS components.

Zones, conduits, and security levels

System work usually starts with the system under consideration, zones, conduits, and risk assessment. Security levels then express target or achieved capability in a defined scope; they should not be used as a loose product marketing label.

Certification and product law

Certification schemes and product laws use IEC 62443 in different ways. A certificate can show process, component, system, or service capability within its stated scope. Product-law conformity still depends on the law, product, requirement, edition, and recognised standard route.

Sources