Security Levels are how IEC 62443 expresses how well a zone, system or component can withstand a certain type of attacker. There are four levels, increasing in the assumed resources, motivation and knowledge of the attacker:
- SL 1 — protection against casual or coincidental exposure.
- SL 2 — protection against an attacker with limited resources acting deliberately.
- SL 3 — protection against an attacker with significant resources and specific IACS knowledge.
- SL 4 — protection against an attacker with extensive resources, such as state actors.
Three variants of Security Level
A common source of confusion is that "Security Level" comes in three variants:
- SL-T (Target) — the security level you aim for a zone, determined on the basis of a risk assessment (IEC 62443-3-2).
- SL-C (Capability) — the level that a system or component can actually deliver, as documented by the vendor.
- SL-A (Achieved) — the level that is actually realised and verified in practice, after implementation.
A zone is only "at level" when SL-A is equal to or higher than SL-T, and that is demonstrated with components whose SL-C is sufficient.
How do you determine an SL-T?
IEC 62443-3-2 describes a risk assessment per zone: what impact would a successful attack have on safety, availability, the environment or finances? A zone with equipment that directly affects the stability of the electricity grid — such as the substation LAN — generally gets a higher SL-T than a zone with only monitoring or reporting functionality.
Practical example
When designing a new substation, a grid operator sets an SL-T of 3 for the substation LAN, because of the direct coupling with protection relays. When procuring industrial switches for this zone, it is then required that the SL-C of the switches is at least SL 3 for the relevant Foundational Requirements, so that after implementation an SL-A of 3 can plausibly be demonstrated and tested during the Site Acceptance Test.
Common mistake
Setting an SL-T without linking it to concrete procurement requirements. The result is that components with a lower security level than intended end up in a critical zone, so that the intended SL-T is never actually achieved.