After zone and conduit security strategy is defined, document the new or upgraded security countermeasures planned to achieve each Target Security Level (SL-T). The conceptual design specification is the design-package companion to the Cybersecurity Requirements Specification (CRS): the CRS states mandatory requirements and constraints; the conceptual design specification describes how the organisation intends to meet them — scope, architecture, cost and schedule.
In the Automation Solution security lifecycle, this aligns with Design-phase deliverables such as detailed security architecture for zones and conduits (Part 2-2). Primary standard content remains Part 3-2; Part 3-3 is used when selecting technical measures against SL-T.
Related: Zone and Conduit Security Strategy | ZCR 6 – CRS | Secure the Countermeasures | ZCR 7 – Approval | Four Ts | Five Ds | Part 3-3 Security Levels | Balancing Security vs Cost | Security Protection Scheme (SPS)
Define the cybersecurity project work like any other engineering project: boundaries of the SUC (or zones) in scope, inclusions and exclusions, interfaces, roles (asset owner, integrator, product supplier), and deliverables through implementation and verification. Tie each work package to the risks and SL-T values it addresses.
Develop or refine the conceptual security architecture that realises the zone and conduit strategy: segmentation and conduits, access control points, monitoring and response placement, and how physical and cyber controls align. Show how planned countermeasures map to SL-T and to Part 3-3 foundational requirements where technical capability is claimed. Reuse and update zone/conduit drawings from the CRS.
Establish order-of-magnitude cost and schedule for the planned countermeasures. Weigh cost and complexity against risk reduction (Balancing Security vs Cost) so asset-owner approval is informed. Update estimates as design iterates toward detailed engineering.