Industrial automation and control systems (IACS) have different threats and constraints than the information technology (IT) world. IEC 62443 is the cybersecurity standard developed specifically for these systems and is the most widely accepted in the industry.
Why Is IEC 62443 Different?
IT security standards usually prioritize confidentiality. In OT environments, availability and integrity come first: stopping a production line can create greater costs than a data leak. IEC 62443 is designed around this difference in priorities.
Parts of the Standard
- General (Part 1): Concepts, terminology, and model definitions.
- Policies and Procedures (Part 2): Security management system, lifecycle processes, and incident management.
- System (Part 3): Security levels (SL), the zone and conduit model, and system security requirements.
- Component (Part 4): Product development lifecycle security and component-level requirements.
Security Levels (SL)
IEC 62443 defines four security levels:
- SL 1: Protection against unintentional events.
- SL 2: Protection against intentional attackers with limited resources.
- SL 3: Protection against skilled attackers using sophisticated methods.
- SL 4: Protection against actors with the highest level of capability.
In practice, the goal is not to reach the highest level in every plant, but to determine the appropriate level for each zone based on risk analysis.
The Zone and Conduit Model
The standard models the system as zones (groups of assets with the same security requirements) and conduits (communication paths between zones). This approach puts firewalls and access rules into a logical structure.
Implementation Approach
- Map the current OT architecture and data flows.
- Conduct a risk assessment to determine zones and target security levels.
- Apply network security and access controls according to the zone-conduit model.
- Establish management processes: change management, vulnerability management, incident response.
- Maintain the posture with continuous monitoring and regular reviews.
Certification and Supplier Alignment
IEC 62443 certification is divided into product and system levels. Product certification shows that a component meets specific security requirements. System certification validates the holistic security state of an installation. Using IEC 62443 compliance as a criterion in supplier selection brings security into the supply chain.
IEC 62443 should be seen not as a checklist but as a framework that keeps OT security sustainable. What matters is not the documentation, but that the processes actually work.
Conclusion
IEC 62443 provides a common language for OT security, clarifying expectations among customers, suppliers, and auditors. For industrial plants, starting the compliance journey with small, manageable steps is the most realistic approach.