← Home

IEC 62443-3-2 – Conceptual Design Specification

After zone and conduit security strategy is defined, document the new or upgraded security countermeasures planned to achieve each Target Security Level (SL-T). The conceptual design specification is the design-package companion to the Cybersecurity Requirements Specification (CRS): the CRS states mandatory requirements and constraints; the conceptual design specification describes how the organisation intends to meet them — scope, architecture, cost and schedule.

In the Automation Solution security lifecycle, this aligns with Design-phase deliverables such as detailed security architecture for zones and conduits (Part 2-2). Primary standard content remains Part 3-2; Part 3-3 is used when selecting technical measures against SL-T.

Teaching note: Paraphrased for learning from IACS conceptual-design course material and related ISA/IEC 62443 practice. Not a verbatim extract of ISA publications or the standard — always refer to published text for normative wording. The conceptual design specification need not be a single file; it may sit beside or within controlled project documents as long as the content is complete and classified appropriately.

Related: Zone and Conduit Security Strategy | ZCR 6 – CRS | Secure the Countermeasures | ZCR 7 – Approval | Four Ts | Five Ds | Part 3-3 Security Levels | Balancing Security vs Cost | Security Protection Scheme (SPS)


What to document

1. Scope of work

Define the cybersecurity project work like any other engineering project: boundaries of the SUC (or zones) in scope, inclusions and exclusions, interfaces, roles (asset owner, integrator, product supplier), and deliverables through implementation and verification. Tie each work package to the risks and SL-T values it addresses.

2. Conceptual system architecture

Develop or refine the conceptual security architecture that realises the zone and conduit strategy: segmentation and conduits, access control points, monitoring and response placement, and how physical and cyber controls align. Show how planned countermeasures map to SL-T and to Part 3-3 foundational requirements where technical capability is claimed. Reuse and update zone/conduit drawings from the CRS.

3. Budgetary cost and schedule estimates

Establish order-of-magnitude cost and schedule for the planned countermeasures. Weigh cost and complexity against risk reduction (Balancing Security vs Cost) so asset-owner approval is informed. Update estimates as design iterates toward detailed engineering.


Relationship to CRS and SPS


Key takeaways