International · International Electrotechnical Commission (IEC) / ISA · IEC 62443

IEC 62443 Industrial Automation and Control Systems Security

The international standard series for securing industrial automation and control systems (IACS) across the IT/OT boundary.

What it is

IEC 62443 is the multi-part standard series for IACS cybersecurity, organised across four groups: General (62443-1-x), Policies and Procedures (62443-2-x), System (62443-3-x) and Component (62443-4-x). Its most-cited concepts are the zone-and-conduit model, Security Levels (SL 1–4), and the Foundational Requirements. It is widely used by utilities, manufacturers and OEMs, and is one of the accepted bases for cyber-hazard obligations under the Australian CIRMP Rules.

Who it applies to

Operators, integrators and product suppliers of industrial control systems - electricity, water, oil & gas, manufacturing, transport and building management.

Requirements

Risk assessment and system design

Identify zones and conduits and assign Security Levels to each.

Identification and authentication

Identify and authenticate users, software processes and devices.

Use control

Restrict privileges; limit the use of networked resources to authorised entities.

System integrity

Protect the integrity of IACS including input validation, session integrity and malicious code detection.

Data confidentiality

Protect the confidentiality of information at rest and in transit.

Restricted data flow

Segment IACS networks through zones and conduits.

Timely response to events

Respond to security violations through continuous monitoring and forensic capability.

Resource availability

Ensure availability of IACS against degradation or denial of essential services.

Read next

Other places this turns up on the site.

Security, engineered around you.

Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.