← Home

IEC 62443-3-2 Criticality Assessment

Criticality assessment rates how severe the negative impact would be if an IACS asset’s information or function were unavailable, unreliable or compromised. It supports the initial / high-level cybersecurity risk view in Part 3-2 (ZCR 2) and later appears in zone/conduit characteristics (ZCR 6.4 records assets with classification, criticality and business value).

Teaching note: Summaries paraphrase ISA/IEC 62443-3-2:2020 concepts and common IACS training practice (including AIC-style criticality for initial risk). They are not a verbatim extract of the standard — always refer to the published text for normative wording and assessment.

Reference: ISA/IEC 62443-3-2:2020 (Clauses 4.3 and 4.7.5)
Related: Cyber Risk Concepts | Consequence | Risk Equation | ZCR 2 – Initial Risk | ZCR 3 – Zones and Conduits | ZCR 6 – CRS


Purpose

Criticality answers: if this asset is interfered with, which consequences matter most? It is not a full threat catalog. It helps prioritise partitioning (ZCR 3), decide whether detailed assessment is warranted (ZCR 4), and document asset importance in the CRS.


Inputs for assessing criticality

Use and develop evidence from:

Those same inputs inform worst-case unmitigated impact in ZCR 2 and consequence scoring in ZCR 5.3 — keep one narrative of “what goes wrong” rather than inventing a second scale. See Consequence.


Criticality AIC method (initial / high-level risk)

A practical method used with Part 3-2 initial risk thinking is to walk each asset (or logical grouping) through Availability, Integrity and Confidentiality:

PropertyQuestion
Availability Assume availability is compromised — what are the consequences?
Integrity Assume integrity is compromised — what are the consequences?
Confidentiality Assume confidentiality is compromised — what are the consequences?

Assign a criticality rating per asset from those answers and record the list. In OT, availability and integrity usually dominate; confidentiality still matters for recipes, formulations, intellectual property and remote-access credentials.

OT note: AIC here is a criticality lens for high-level risk, not a claim that IT “CIA triad” priorities apply unchanged. Prefer the organisation’s consequence categories when ranking severity.

Where criticality sits in Part 3-2


Key Takeaways