← Home

IEC 62443-3-2 Threats

A threat is who or what is able to exploit the system, and how. In Part 3-2 detailed assessment, threats are identified per zone or conduit (ZCR 5.1). The wider threat environment is later documented in the CRS (ZCR 6.6).

Teaching note: Summaries paraphrase ISA/IEC 62443-3-2:2020 and common IACS training material for learning. They are not a verbatim extract of the standard — always refer to the published text for normative wording and assessment.

Reference: ISA/IEC 62443-3-2:2020, Clauses 4.6.2 and 4.7.7
Related: Cyber Risk Concepts | Risk Equation | Vulnerabilities | Consequence | ZCR 5 | Documentation | ZCR 6.6 – Threat environment | Network Attacks | Industrial Cyber Attacks


Threat source

The threat source is the entity that can manifest the threat. Typical classes for IACS include:

Useful threat records (ZCR 5.1) typically capture source, capability or skill, possible vectors and affected assets. Grouping into classes is acceptable when a raw list would be unwieldy.


Threat environment

The threat environment is the set of current and emerging threats that could affect the SUC. Part 3-2 expects the CRS to name intelligence sources and describe that environment (ZCR 6.6). Common feeds include:


Threat vector

A threat vector is the means or path used to compromise the system. Training material often groups vectors using the STRIDE-style themes below (useful as a checklist, not as Part 3-2 normative language):


Threat statements and catalog

A threat statement narrates a realistic scenario that links source, vector and target. Examples:

A threat catalog is the set of realistic scenarios evaluated during the detailed cybersecurity risk analysis (ZCR 5). Keep it plant- and zone-specific — not a generic internet threat list.


Where threats sit in Part 3-2


Key Takeaways