Zones, Conduits, and Security Levels

Zones, conduits, and security levels are system-design concepts. They belong to a defined system under consideration and its risk assessment, not to a loose product family or a whole site label.

System under consideration

IEC 62443-3-2:2020 establishes requirements for defining a system under consideration for an IACS. The boundary decides which assets, interfaces, users, communication paths, operating modes, and assumptions belong in the risk assessment.

A useful boundary is specific enough to review. A factory, a cloud service, a machine line, a remote-access path, or a SCADA deployment may be relevant, but the page should name the actual system and the functions it supports. Without that boundary, a zone model becomes a network diagram with security labels attached.

Zones and conduits

IEC 62443-3-2 then partitions the system under consideration into zones and conduits. This is the point at which risk, architecture, and responsibility meet.

Zone

A grouping of assets inside the system boundary that should share similar security requirements for the analysis.

Conduit

A communication path between zones that needs its own risk treatment and security requirements.

This structure keeps the assessment practical. A safety PLC, engineering workstation, historian, remote-access service, fieldbus, controller network, and enterprise network should not be treated as one flat trust area if their exposure, consequences, or security needs differ.

Security levels

Public IEC material describes IEC 62443-3-2 as establishing target security levels for each zone and conduit. IEC 62443-3-3 then provides detailed control system requirements and capability security levels. A security level is not a general quality score. It is tied to a defined system, zone, conduit, threat environment, and set of requirements.

  • define the system under consideration before assigning levels;
  • partition the system into zones and conduits;
  • assess risk for each zone and conduit;
  • establish SL-T for each zone and conduit;
  • document the security requirements that follow from the target.

Product limit

A product supplier can provide component capability evidence, secure development evidence, and product documentation. That evidence still has to be placed into the deployed architecture. The same component can sit in different zones, connect through different conduits, and face different risk in different installations.

This is also why system integrators and asset owners remain visible in IEC 62443. The asset owner usually owns the risk decision for the operating IACS. The integration service provider may design or assist with partitioning, detailed risk assessment, and technical measures. The product supplier usually contributes capability information and product support, not the final system risk conclusion.

Sources