← Home

ISA/IEC 62443 Security for Industrial Automation and Control Systems

Overview

The ISA/IEC 62443 series is the internationally recognized body of standards, technical reports, and related guidance for securing industrial automation and control systems (IACS). It began as the ISA99 initiative within the International Society of Automation and was later adopted by the International Electrotechnical Commission as IEC 62443. The same content is published in the United States as ANSI/ISA 62443. These designations are interchangeable; this site uses ISA/IEC 62443 as a convenient shorthand that reflects both publishing paths. When purchasing ISA editions, the ANSI/ prefix applies to standards only—not to technical reports.

ISA/IEC 62443 series overview
Figure 1 – ISA/IEC 62443 series overview showing general, policies and procedures, system, component, profiles, and evaluation documents.

Standards Family

IACS Cybersecurity Roles
Cybersecurity Acceptance Testing
Incident Response and Recovery
ISO/IEC 27001, ISO/IEC 27002 and the ISA/IEC 62443 Series for Operational Technology Environments

The organization of the documents in the ISA/IEC 62443 series is shown in Figure 1 (above). Browse the standards by series part below.

ISA/IEC 62443-1 General ISA/IEC 62443-2 Policies & Procedures ISA/IEC 62443-3 System
TS 62443-1-1 Concepts and Models
IEC 62443-1-1 Clause 4 – The Situation
IEC 62443-1-1 Clause 5.7 – Policies, Procedures & Guidelines
IEC 62443-1-1 Clause 5.10 – Security Levels
IEC 62443-1-1 Clause 6 – Models
62443-1-2 Glossary, Terms & Abbreviations
62443-1-3 System Security Conformance Metrics
TR/TS 62443-1-4 IACS Security Lifecycle and Use Cases
TR/TS 62443-1-5 Security Profiles
IEC 62443 Security Profiles (TS 62443-1-5 / Part 5)
TR/TS 62443-1-6 Application in IIoT
62443-2-1 Security Program Requirements for IACS Asset Owners
IEC 62443-2-1 Cybersecurity Management System (CSMS) (2010)
IEC 62443-2-1 Clause 3 - Security Program Requirements (2024)
IEC 62443-2-1 – Security Program and Risk Assessment
IEC 62443-2-1 Clause 4.2 – Maturity Levels
IEC 62443-2-1 Clause 5 – Conformance and Assessment
IEC 62443-2-1 Clause 6 – Organizational Security Measures
IEC 62443-2-1 Clause 7 – Configuration Management
IEC 62443-2-1 Clause 8 – Network and Communications Security
IEC 62443-2-1 Clause 9 – Component Security
IEC 62443-2-1 Clause 10 – Protection of Data
IEC 62443-2-1 Clause 11 – User Access Control
IEC 62443-2-1 Clause 12 – Event and Incident Management
IEC 62443-2-1 Clause 13 – System Integrity and Availability
IEC 62443-2-1 Cybersecurity Awareness Training (SPE1-ORG1.4/1.5)
62443-2-2 IACS Security Protection Scheme
IEC 62443-2-2 Security Protection Scheme (SPS)
IEC 62443-2-2 Automation Solution Security Lifecycle
62443-2-3 Patch Management in the IACS Environment
IEC 62443-2-3 Patch Management in the IACS Environment
62443-2-4 Security Program Requirements for IACS Service Providers
IEC 62443-2-4 Security Program Requirements for IACS Service Providers
TR/TS 62443-2-5 Implementation Guidance for IACS Asset Owners (planned)
TR/TS 62443-3-1 Security Technologies for IACS
IEC 62443-3-1 – Overview (Clauses 1–4)
IEC 62443-3-1 Clause 5 – Authentication and Authorisation
5.1 Role-based authorisation (RBAC)
5.2 Password authentication
5.3 Challenge/response authentication
5.4 Physical/token authentication
5.5 Smart card authentication
5.6 Biometric authentication
5.7 Location-based authentication
5.8 Password distribution and management
5.9 Device-to-device authentication
IEC 62443-3-1 Clause 6 – Filtering / Blocking / Access Control
6.1 Network firewalls
6.2 Host-based firewalls
6.3 Virtual networks
IEC 62443-3-1 Clause 7 – Encryption and Data Validation
7.1 Symmetric key encryption
7.2 Public key encryption and key distribution
7.3 Virtual private networks (VPNs)
IEC 62443-3-1 Clause 8 – Management, Audit, Monitoring and Detection
8.1 Log auditing utilities
8.2 Virus and malicious code detection
8.3 Intrusion detection systems
8.4 Vulnerability scanners
8.5 Forensics and analysis tools
8.6 Host configuration management
8.7 Automated software management
IEC 62443-3-1 Clause 9 – IACS Computer Software
9.1 Server and workstation operating systems
9.2 Real-time and embedded operating systems
9.3 Web technologies
IEC 62443-3-1 Clause 10 – Physical Security Controls
10.1 Physical protection
10.2 Personnel security
62443-3-2 Security Risk Assessment for System Design
IEC 62443-3-2 – Documentation
IEC 62443-3-2 Cyber Risk Concepts
IEC 62443-3-2 – Understand Risk
IEC 62443-3-2 – Develop a Plan
IEC 62443-3-2 – Four Ts of Managing Risk
IEC 62443-3-2 – Benefits of a Cyber Risk Assessment
IEC 62443-3-2 – Balancing Security vs Cost
IEC 62443-3-2 – Prepare for an Assessment
IEC 62443-3-2 Risk Equation
IEC 62443-3-2 Threats
IEC 62443-3-2 Vulnerabilities
IEC 62443-3-2 Consequence
IEC 62443-3-2 Criticality Assessment
IEC 62443-3-2 – Bowtie Diagrams
IEC 62443-3-2 – Mitigated Likelihood and Residual Risk
IEC 62443-3-2 Clause 4 – Zone, Conduit and Risk Assessment Requirements
IEC 62443-3-2 Clause 4.2 – Identify the SUC (ZCR 1)
IEC 62443-3-2 Clause 4.3 – Initial Cybersecurity Risk Assessment (ZCR 2)
IEC 62443-3-2 Clause 4.4 – Partition into Zones and Conduits (ZCR 3)
IEC 62443-3-2 Clause 4.5 – Risk Comparison (ZCR 4)
IEC 62443-3-2 Clause 4.6 – Detailed Cybersecurity Risk Assessment (ZCR 5)
IEC 62443-3-2 Clause 4.7 – Document Requirements, Assumptions and Constraints (ZCR 6)
IEC 62443-3-2 Clause 4.8 – Asset Owner Approval (ZCR 7)
IEC 62443-3-2 – Zone and Conduit Security Strategy
IEC 62443-3-2 – Conceptual Design Specification
62443-3-3 System Security Requirements and Security Levels
IEC 62443-3-3 Clause 4 – Common Control System Security Constraints
IEC 62443-3-3 Foundational Requirements (FR1–FR7)
IEC 62443-3-3 Clause 5 – FR1 - Identification and Authentication Control
IEC 62443-3-3 Clause 6 – FR2 - Use Control
IEC 62443-3-3 Clause 7 – FR3 - System Integrity
IEC 62443-3-3 Clause 8 – FR4 - Data Confidentiality
IEC 62443-3-3 Clause 9 – FR5 - Restricted Data Flow
IEC 62443-3-3 Clause 10 – FR6 - Timely Response to Events
IEC 62443-3-3 Clause 11 – FR7 - Resource Availability
IEC 62443-3-3 – Using SL-T to Select SRs and REs
IEC 62443-3-3 FR and SL Vector (Annex A)
IEC 62443-3-3 Annex B – SR/RE Mapping to Security Levels
IEC 62443-3-3 Security Levels (Annex A.3.2)
ISA/IEC 62443-4 Components ISA/IEC 62443-5 Profiles ISA/IEC 62443-6 Evaluation
62443-4-1 Secure Product Development Lifecycle Requirements
IEC 62443-4-1 Secure Product Development Lifecycle
IEC 62443-4-1 Clause 5 – Security Management (SM)
IEC 62443-4-1 Clause 6 – Specification of Security Requirements (SR)
IEC 62443-4-1 Clause 7 – Secure by Design (SD)
IEC 62443-4-1 Clause 8 – Secure Implementation (SI)
IEC 62443-4-1 Clause 9 – Security Verification and Validation Testing (SVV)
IEC 62443-4-1 Clause 10 – Management of Security-Related Issues (DM)
IEC 62443-4-1 Clause 11 – Security Update Management (SUM)
IEC 62443-4-1 Clause 12 – Security Guidelines (SG)
62443-4-2 Technical Security Requirements for IACS Components
IEC 62443-4-2 Technical Security Requirements for IACS Components
IEC 62443-4-2 Clause 4 – Common Component Security Constraints (CCSC)
IEC 62443-4-2 Clause 5 – Component Requirements - FR1 - Identification and Authentication Control
IEC 62443-4-2 Clause 6 – Component Requirements - FR2 - Use Control
IEC 62443-4-2 Clause 7 – Component Requirements - FR3 - System Integrity
IEC 62443-4-2 Clause 8 – Component Requirements - FR4 - Data Confidentiality
IEC 62443-4-2 Clause 9 – Component Requirements - FR5 - Restricted Data Flow
IEC 62443-4-2 Clause 10 – Component Requirements - FR6 - Timely Response to Events
IEC 62443-4-2 Clause 11 – Component Requirements - FR7 - Resource Availability
IEC 62443-4-2 Clause 12 – Software Application Requirements
IEC 62443-4-2 Clause 13 – Embedded Device Requirements
IEC 62443-4-2 Clause 14 – Host Device Requirements
IEC 62443-4-2 Clause 15 – Network Device Requirements
IEC 62443-4-2 Annex A – Device Categories
IEC 62443-4-2 Annex B – CR/RE Mapping to Security Levels
62443-5-x Profile Documents
IEC 62443-5 Security Profiles
TR/TS 62443-6-1 Security Evaluation Methodology for 62443-2-4
TR/TS 62443-6-2 Security Evaluation Methodology for 62443-4-2