Developed through ISA99 and IEC TC 65/WG 10, it addresses terminology, security programs, service providers, system risk and requirements, secure product development, and components. Different parts apply to asset owners, integrators, service providers, product suppliers, and lifecycle stages.
Applying IEC 62443 begins by identifying the system and roles, selecting applicable parts, and using risk assessment to define requirements. IEC 62443-3-2 addresses partitioning the system under consideration into zones and conduits, assessing risk, and documenting target security levels. IEC 62443-3-3 defines system security requirements associated with foundational requirements and capability security levels.
Key points
Select the relevant document“IEC 62443 compliant” is incomplete without the applicable part, edition, role, system or product scope, requirements, and assessment basis.
Use zones and conduitsGroup assets with compatible security needs, define controlled communication paths, assess risk for each, and document the target security level and requirements.
Distinguish security levelsTarget, capability, and achieved security levels answer different questions; they are not a generic one-to-four maturity score for an organization.
Treat security as a lifecycleAsset-owner programs, supplier development practices, service delivery, system integration, maintenance, patching, incident handling, and decommissioning involve different responsibilities.
Important limitationIEC 62443 is not a single product certificate or a shortcut to secure operation. A component certificate does not establish that an integrated system, site program, configuration, or operating process conforms. Cybersecurity measures must also be engineered so they do not undermine functional safety or required availability.