← Home
IEC 62443-3-2 Threats
A threat is who or what is able to exploit the system, and how. In Part 3-2
detailed assessment, threats are identified per zone or conduit
(ZCR 5.1).
The wider threat environment is later documented in the CRS
(ZCR 6.6).
Teaching note: Summaries paraphrase ISA/IEC 62443-3-2:2020 and common IACS
training material for learning. They are not a verbatim extract of the standard — always
refer to the published text for normative wording and assessment.
Reference: ISA/IEC 62443-3-2:2020, Clauses 4.6.2 and 4.7.7
Related:
Cyber Risk Concepts
|
Risk Equation
|
Vulnerabilities
|
Consequence
|
ZCR 5
|
Documentation
|
ZCR 6.6 – Threat environment
|
Network Attacks
|
Industrial Cyber Attacks
Threat source
The threat source is the entity that can manifest the threat. Typical
classes for IACS include:
- Individuals — authorised or unauthorised, internal or external personnel
(including non-malicious staff who make mistakes).
- Groups — organised crime, activist groups, nation-state teams.
- Hardware / software — faulty components, misbehaving applications,
compromised devices.
- Environmental events — fires, floods and other physical events that can
disrupt IACS availability or integrity.
- Malware — ransomware, worms and targeted ICS malware acting as an
automated threat agent.
Useful threat records (ZCR 5.1) typically capture source, capability or skill, possible
vectors and affected assets. Grouping into classes is acceptable when a raw list would be
unwieldy.
Threat environment
The threat environment is the set of current and emerging threats that
could affect the SUC. Part 3-2 expects the CRS to name intelligence sources and describe
that environment (ZCR 6.6). Common feeds include:
- CISA (Cybersecurity & Infrastructure Security Agency) and similar national CERTs
- ENISA and other regional agencies
- IACS product suppliers and vendor advisories
- Anti-malware vendors
- Industry advisory groups and ISACs
- Local government and sector regulators
Threat vector
A threat vector is the means or path used to compromise the system.
Training material often groups vectors using the STRIDE-style themes below (useful as a
checklist, not as Part 3-2 normative language):
- Spoofing — assume the identity of another user or device.
- Tampering — unauthorised changes to program, configuration or data.
- Information disclosure — unauthorised redirection or exposure of data.
- Denial of service (DoS) — delaying or blocking the flow of information
or control.
Threat statements and catalog
A threat statement narrates a realistic scenario that links source, vector
and target. Examples:
- A non-malicious employee opens a phishing e-mail, compromising access credentials and
enabling an outside attacker to reach sensitive data.
- A non-malicious employee physically accesses the process control zone and plugs a USB
memory stick into a PC.
- Authorised support personnel logically access the process control zone using an infected
laptop that becomes a vector for malware infection.
A threat catalog is the set of realistic scenarios evaluated during the
detailed cybersecurity risk analysis (ZCR 5). Keep it plant- and zone-specific — not a
generic internet threat list.
Where threats sit in Part 3-2
- ZCR 2
uses threat intelligence to size worst-case stakes; it does not require a finished catalog.
- ZCR 5.1
builds the threat list per zone/conduit.
- ZCR 6.6
records the threat environment in the CRS.
Key Takeaways
- Threat = source + capability + path to the asset.
- Threat statements turn that into scenarios the risk team can score.
- Detailed assessment owns the catalog; the CRS captures the environment and sources.