← Home

IEC 62443-3-2 Vulnerabilities

A vulnerability is a flaw or weakness in a system’s design, implementation or operation that could be exploited to compromise the system. Part 3-2 requires identification of known vulnerabilities (including access points) for each zone or conduit in the detailed assessment (ZCR 5.2).

Teaching note: Summaries paraphrase ISA/IEC 62443-3-2:2020 and common IACS training material for learning. They are not a verbatim extract of the standard — always refer to the published text for normative wording and assessment.

Reference: ISA/IEC 62443-3-2:2020, Clause 4.6.3
Related: Cyber Risk Concepts | Risk Equation | Threats | Consequence | ZCR 5 | Documentation | Prepare for an Assessment | Bowtie Diagrams | IEC 62443-2-3 Patch Management | Network Discovery and Scanning


Vulnerability vs cyber risk

Vulnerability analysis is not cyber risk analysis. Not every vulnerability represents material risk to the OT environment, and exploiting a vulnerability does not always produce a consequence that matters to the organisation. Vulnerability work finds and classifies weaknesses; risk assessment adds threat realism and consequence/impact (risk equation).

Assessment results feed the detailed risk assessment as an input (ZCR 5.2 and ZCR 5.13 supporting evidence) — they do not replace it.


Classes of vulnerability

IACS weaknesses commonly fall into the classes below. Use them as a discovery checklist when building the ZCR 5.2 list.

Policy and procedures

Architecture and design

Configuration and maintenance

Physical

Software development

Communication and network


Discovery questions by layer

When listing vulnerabilities for a zone or conduit (ZCR 5.2), walk the path an attacker or malware would take: first the access points, then the internal LAN(s) inside the zone, then the end devices. The prompts below turn that path into workshop questions — use them alongside the classes above and any prior vulnerability assessments.

Access points

What vulnerabilities exist that would allow an attacker or malware to pass through or circumvent access controls at access points?

Internal networks (LAN within the zone)

What vulnerabilities exist that would allow an attacker or malware to compromise the LAN(s) within the zone?

End devices

What vulnerabilities exist at the end devices (for example computers, industrial controllers) that would allow an attacker or malware to compromise the device?

Teaching note: Threats succeed by exploiting one or more of these layers. Recording vulnerabilities by access point, LAN and end device makes the later threat-vector and countermeasure discussion concrete (Threats, Bowtie Diagrams).

IACS cybersecurity vulnerability assessment

An IACS cybersecurity vulnerability assessment defines, identifies and classifies security vulnerabilities in an IACS and its related network infrastructure. It evaluates design, implementation, configuration, operation and management; judges adequacy of security measures; and identifies known component vulnerabilities.

It does not by itself determine consequence or organisational risk ranking.

Four types (least to most invasive)

TypeWhat it doesTypical techniques
High-level (gap) Compare practices with standards and peer norms Interviews, walk-throughs, drawing/config review, policy review, questionnaires
Passive Discover network and issues without active probing Drawing review, walk-through, traffic capture/analysis, ARP tables, device data, config review, vulnerability database research
Active Invasive discovery of devices and weaknesses Network scanners (for example Nmap, ping/ARP/IP sweeps), vulnerability scanners (for example OpenVAS, Nessus, Nexpose)
Penetration test Extreme invasion — exploit and attempt unauthorised access Attacker perspective; exploit known/unknown weaknesses; validate countermeasures
OT caution: Active scans and penetration tests can disrupt real-time control. Authorise methods explicitly, prefer offline or maintenance windows, and escalate invasiveness only when the risk of testing is accepted. See network discovery and scanning for defender vs attacker use of Nmap-class tools and safer IACS practices.

Conducting a high-level assessment

  1. Identify benchmark standards.
  2. Gather information (drawings, walk-throughs, interviews, configs).
  3. Compare performance with the benchmarks.
  4. Document and report results.

Vulnerability Assessment Report

The Vulnerability Assessment Report records what was examined and what was found so results can feed ZCR 5.2 and be archived with the detailed assessment (ZCR 5.13). See also the document catalogue on Documentation.

Include at least:

Those finding classes align with the discovery questions by layer and the vulnerability classes above. Protect the report — it often lists weaknesses an attacker would value.


Assessment tools (including CSET)

Common supports include custom spreadsheets/databases and structured tools such as CSET (Cybersecurity Evaluation Tool from CISA / formerly DHS).

CSET strengths

CSET limitations

Typical CSET process

  1. Form a team
  2. Add assessment information
  3. Select mode and standards
  4. Determine the security level
  5. Build a network diagram
  6. Answer questions
  7. Analyse results

Reference standards selectable in CSET commonly include ISA-62443-4-1, NIST CSF, NERC CIP, NIST SP 800-82, NIST SP 800-53, DoD Instruction 8500.2, NRC RG 5.71, FIPS 199 and CFATS RBPS guidance (tool version dependent).


Where vulnerabilities sit in Part 3-2


Key Takeaways