Cyber risk is the possibility that an Industrial Automation and Control System (IACS) is compromised through unauthorised access, use, modification, disruption or destruction — with adverse effects on operations, personnel safety, the environment or the organisation.
ISA/IEC 62443 applies general risk-management ideas to IACS design through ISA/IEC 62443-3-2 (security risk assessment for system design). The Clause 4 zone and conduit requirements (ZCRs) turn these concepts into a repeatable engineering workflow. Part 3-3 then supplies the system security requirements used to meet the resulting target security levels (SL-T).
Reference: ISA/IEC 62443-3-2:2020 (risk concepts informing Clause 4 and Annex B)
Related:
Documentation |
Understand Risk |
Develop a Plan |
Benefits of a Risk Assessment |
Balancing Security vs Cost |
Prepare for an Assessment |
Risk Equation |
Threats |
Vulnerabilities |
Consequence |
Criticality Assessment |
Bowtie Diagrams |
Mitigated Likelihood and Residual Risk
|
Zone, Conduit and Risk Assessment (Clause 4)
|
ZCR 2 – Initial Risk Assessment
|
ZCR 5 – Detailed Risk Assessment
|
SP and Risk Assessment
|
IEC 62443-3-3 Security Levels
|
IEC 62443-1-1 Security Levels
ZCR pages: ZCR 1 | ZCR 2 | ZCR 3 | ZCR 4 | ZCR 5 | ZCR 6 | ZCR 7
Cyber risk is assembled from a small set of building blocks. Use this hub for orientation; each component has its own page so detail is not duplicated across Clause 4 ZCR pages.
| Component | Role in Part 3-2 | Page |
|---|---|---|
| Risk equation | Threat × Vulnerability × Consequence (and Likelihood × Consequence in practice); unmitigated vs residual; matrix scoring | Risk Equation |
| Threats | Sources, vectors, statements and catalog (ZCR 5.1); threat environment in CRS (ZCR 6.6) | Threats |
| Vulnerabilities | Weakness classes and assessment methods feeding ZCR 5.2 | Vulnerabilities |
| Consequence | Worst-case outcomes and impact scoring (ZCR 2, ZCR 5.3) | Consequence |
| Criticality | Asset AIC / impact ranking for initial risk, zoning and CRS (ZCR 2, 3, 6.4) | Criticality Assessment |
Conceptually: Risk = Threat × Vulnerability × Consequence. Practically, threat and vulnerability combine into likelihood, then Risk = Likelihood × Consequence on the corporate matrix. Full treatment, including unmitigated vs residual and an example matrix, is on the Risk Equation page.
Risk tolerance (tolerable risk in Part 3-2) is the level of cyber risk the organisation is prepared to live with. Risks above that bar need treatment; those below may be accepted with monitoring. The bar is an organisational policy choice and is recorded in the CRS (ZCR 6.8).
Part 3-2 turns the concepts above into a design-time method. Read the Clause 4 overview for the full workflow; the ZCR sequence in brief is:
After design, implement and verify controls using ISA/IEC 62443-3-3, and keep residual risk under review across the lifecycle (operations programme support sits mainly in Part 2-1).
The SUC is the defined set of IACS assets in scope for the assessment — controllers, HMIs, servers, networking, safety systems and supporting infrastructure needed for the automation solution. Every asset belongs to a zone or a conduit (ZCR 1).
Zones group assets with similar cybersecurity needs. Conduits are the controlled communications paths between (or within) zones. Detailed risk assessment and SL-T assignment run at zone/conduit level (ZCR 3, ZCR 5). Zone/conduit concepts are introduced in Part 1-1.
| 62443-3-2 | Output | 62443-3-3 |
|---|---|---|
| Risk assessment for system design (Clause 4 ZCRs) | Target Security Levels (SL-T) per zone/conduit | System security requirements and capability levels (SL-C) to meet SL-T |
Industrial organisations drive cyber risk down to a tolerable level while protecting safety, availability, reliability and continuity. Defence in depth, segmentation, access control, hardening and patching mainly reduce likelihood; safety systems, redundancy and recovery planning mainly limit consequence.
The practical goal is to secure the SuC so that even if a cyber incident compromises one or more components, intolerable consequences still do not occur. That is a long-term design and programme decision, not a one-off scan.
Part 3-2 supplies the risk/zone/SL-T method; the asset owner’s Security Program (Part 2-1) owns the ongoing policies that keep those decisions alive. Start with Understand Risk, then Prepare for an Assessment.