Knowledge centre
IEC 62443 knowledge centre
IEC 62443 is the main international series of standards for cybersecurity of industrial automation and control systems (IACS). This knowledge centre offers its own summaries, practical explanations and visualisations — and does not replace the official standard publications.
7
Foundational Requirements
7
Parts of the standard
4
Roles
Foundational Requirements
The seven fundamental security requirements, explained interactively with OT examples.
ViewZones & conduits
Interactive example architecture of an electricity substation.
ExploreParts of the standard
Own summaries of the seven most widely used parts of IEC 62443.
ViewRoles
Asset owner, system integrator, product supplier and service provider.
ViewParts of the standard
Own summaries — not a literal reproduction of the official standard text.
62443-1-1
Concepts and models
Introduces the common terminology, concepts and models (including zones and conduits) used throughout the rest of the series of standards.
62443-2-1
Security programme requirements for the asset owner
Describes how an organisation sets up and maintains a Cybersecurity Management System (CSMS) for its IACS environment.
62443-2-4
Requirements for service providers
Sets requirements for the security programme of organisations that provide integration and maintenance services to asset owners.
62443-3-2
Risk assessment for zone and conduit design
Describes the methodology for defining zones and conduits and setting a Security Level Target (SL-T) per zone based on risk.
62443-3-3
System security requirements and security levels
Translates the seven Foundational Requirements into concrete, testable system requirements per Security Level (SL 1 to 4).
62443-4-1
Secure product development lifecycle
Sets requirements for the development process of products, from requirements and secure design to testing, patch policy and end-of-life policy.
62443-4-2
Technical security requirements for IACS components
Translates the Foundational Requirements into concrete technical requirements at component level (embedded devices, network components, host and software applications).
Roles within IEC 62443
Asset Owner
The organisation that actually operates the IACS environment — for example a grid operator or energy producer — and is ultimately responsible for the risk.
System Integrator
The party that brings together IACS components from different suppliers into a working, secure system and delivers it to the asset owner.
Product Supplier
The manufacturer of IACS components such as PLCs, RTUs, relays, HMIs and network equipment.
Service Provider
The party that provides ongoing services to the asset owner, such as remote maintenance, monitoring or management of OT systems.