Skip to content
IACS RadarIndustrial Cyber Exposure & Intelligence
Back to knowledge centre

62443-2-1

IEC 62443-2-1 — Security programme requirements for the asset owner

Describes how an organisation sets up and maintains a Cybersecurity Management System (CSMS) for its IACS environment.

For which role

Asset owners (for example grid operators and energy companies).

Key topics

  • Risk assessment and risk management
  • Policy, organisation and awareness
  • Asset inventory and lifecycle management
  • Incident response and recovery

Expected results

  • A documented and maintained CSMS
  • Periodic risk assessments of the IACS environment
  • A practised incident response process

Relationship to other parts of the standard

Forms the organisational framework within which the technical requirements from -3-3 and -4-2 are applied.

Practical example from the energy sector

A grid operator maintains a current asset inventory of all RTUs and protection relays in substations, including firmware versions, as part of the CSMS.