Back to knowledge centre
62443-2-1
IEC 62443-2-1 — Security programme requirements for the asset owner
Describes how an organisation sets up and maintains a Cybersecurity Management System (CSMS) for its IACS environment.
For which role
Asset owners (for example grid operators and energy companies).
Key topics
- •Risk assessment and risk management
- •Policy, organisation and awareness
- •Asset inventory and lifecycle management
- •Incident response and recovery
Expected results
- •A documented and maintained CSMS
- •Periodic risk assessments of the IACS environment
- •A practised incident response process
Relationship to other parts of the standard
Forms the organisational framework within which the technical requirements from -3-3 and -4-2 are applied.
Practical example from the energy sector
A grid operator maintains a current asset inventory of all RTUs and protection relays in substations, including firmware versions, as part of the CSMS.