Tec Nikan
فارسی
Talk to us
All news

IEC 62443 Defines Roles, Four Security Levels and a Full Lifecycle

The only globally recognised consensus standards written for industrial control systems set out asset owner, integrator and manufacturer roles, SL 1 to SL 4, and zones with conduits.

IEC 62443industrial controlsecurity levelsstandardsOT

The IEC 62443 series is the set of internationally recognised consensus standards written specifically for cybersecurity in industrial automation and control systems. It defines roles for asset owners, integrators and product manufacturers, four Security Levels from SL 1 to SL 4, a zone concept with conduits between zones, and a lifecycle running from risk analysis through to operations.

Being written for control systems rather than adapted from IT security is the property that matters, and it shows up in the priorities. IT security orders its goals as confidentiality, integrity, availability. Industrial control inverts that: a process that stops unexpectedly can be dangerous and is certainly expensive, so availability leads and confidentiality frequently trails. Guidance transplanted from IT tends to recommend controls that are correct in an office and unacceptable on a plant floor.

The role separation is what makes the standard usable rather than overwhelming. A product manufacturer is not responsible for how a plant segments its network, and an asset owner is not responsible for a vendor's secure development lifecycle. Knowing which role you occupy narrows a large multi-part series to a readable subset — and confusion about that is the most common reason teams conclude the standard is impenetrable.

Source: Fortinet

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.