← Home

IEC 62443-3-2 – Zone and Conduit Security Strategy

Conceptual design turns assessment outcomes into a workable protection approach per zone and per conduit. With zones and conduits identified, review the risk-assessment results, confirm Target Security Level (SL-T), identify physical and cyber access points, and develop a multi-faceted strategy — typically using the Five Ds — for each access point.

This page is Part 3-2 teaching for the design-for-assessment workflow. It is not a separate ZCR. Normative zone partitioning, SL-T and CRS content live in Clause 4; Part 3-3 supplies the technical requirement catalogue when sizing measures to SL-T. The Automation Solution lifecycle Design phase points here from Part 2-2.

Teaching note: Paraphrased for learning from IACS conceptual-design course material and related ISA/IEC 62443 practice. Not a verbatim extract of ISA publications or the standard — always refer to published text for normative wording.

Related: ZCR 3 – Zones and Conduits | ZCR 5 | ZCR 6 – CRS | Part 3-3 Security Levels | Four Ts | Five Ds | Conceptual Design Specification | Vulnerabilities / access points | Defence in Depth


Strategy workflow

  1. Identify zones and conduits — Use the partition from ZCR 3 and keep drawings and characteristics current in the CRS.
  2. Review risk-assessment results for each zone or conduit — Interpret the risk profile, highest consequences, leading threats/vulnerabilities, recommendations and SL-T (see ZCR 5). Apply the Four Ts where residual risk still needs a management decision.
  3. Confirm Target Security Level — SL-T is the design objective for that partition (Security Levels).
  4. Identify physical and cyber access points — Every logical and physical entry path is a candidate for treatment (Vulnerabilities, CRS zone/conduit characteristics).
  5. Develop a 5D physical and cyber strategy for each access point — For each threat or access path, plan how to deter, detect, delay, deny and defeat (Five Ds). Harmonise with physical security policy (Part 2-1 ORG 3).
  6. Select technical and organisational measures — Map treated risks to Part 3-3 system requirements (and Part 2-1 programme measures) so capability can meet SL-T; document planned countermeasures in the conceptual design specification and CRS.

5D protection strategy

For each zone and conduit, develop a physical and cyber protection strategy based on the risk-assessment results, SL-T and the CRS. Apply the Five Ds (Deter, Detect, Delay, Deny, Defeat) so the strategy is multi-faceted. Harmonise physical and cyber policies (Part 2-1 ORG 3).

Use a 5D strategy map: list threats (or access-point scenarios) in the left column, then record at least one mitigation under each D where risk justifies it.

Threat Deter Detect Delay Deny Defeat
Unauthorised remote access Warning banner on remote login; policies stating prosecution of intruders Host intrusion detection (HIDS); event / authentication logs; SIEM alerts Security hardening of jump hosts; patching; encryption; session / access controls Firewall rules; VPN with allow-lists; least-privilege access; IPS Incident-response procedures; revoke sessions / isolate hosts; preserve forensic evidence
Malware introduction Acceptable-use and media policies; warning banners Anti-virus; IDS; email / URL filtering; SIEM Patching; hardening; network segmentation; honeypot Application whitelisting; firewall; removable-media controls Malware removal tools; IR playbooks; containment via IPS

Repeat the map for every high-risk threat and access point in that zone or conduit, then carry planned countermeasures into the conceptual design specification and CRS. Full Five D definitions and cyber tool lists: Five Ds of Treating Risk.


Why per zone and conduit

Different partitions face different threats, consequences and SL-T values. A plant-wide control set either over-protects low-risk areas or under-protects high-risk ones. Strategy per zone and conduit keeps protection proportionate and makes access-point ownership clear for designers and operators.


Key takeaways