IEC 62443 — Industrial cybersecurity
Understand the roles, zones, conduits, security levels and secure product lifecycle used to protect industrial automation and control systems.
After this module, you should be able to:
- Describe the IEC 62443 family and stakeholder roles
- Use zones and conduits to structure risk analysis
- Distinguish system and component security requirements
- Connect secure development with operational defence
Industrial cybersecurity is a shared system responsibility.
The IEC 62443 series addresses cybersecurity for industrial automation and control systems across asset owners, service providers, system integrators and product suppliers. Different parts cover policy, system requirements, secure development and component capabilities.
Zones group assets with common security needs; conduits control communications between zones. Security levels express required resistance against classes of attacker capability. A component capability does not by itself establish the achieved security of the installed system.
Translate the framework into controlled engineering work.
| Area | Question | Typical evidence |
|---|---|---|
| Risk and policy | What assets, threats, consequences and governance apply? | Cybersecurity management and risk records |
| Zones and conduits | Which assets share needs and how may information cross boundaries? | Security architecture |
| System requirements | What foundational controls and target levels are needed? | System security requirements |
| Product development | How are threats, defects, updates and disclosure managed? | Secure development lifecycle evidence |
| Operations | How are access, monitoring, backups and patching sustained? | Operational procedures and records |
Apply the current controlled source
This module is an orientation. Confirm the applicable edition, amendments, adopted regional version, contractual commitments and sector-specific interpretations before defining compliance.
Use a risk-based application sequence.
- 1. Identify the industrial function, consequence, assets and responsible organisations
- 2. Partition assets into zones and define necessary conduits
- 3. Assess risk and set target security requirements and levels
- 4. Allocate controls to products, system configuration and operational procedures
- 5. Verify the integrated system, including remote access and degraded operation
- 6. Maintain vulnerability monitoring, patch qualification and incident response
Worked application: remote maintenance gateway
The gateway sits in a conduit between an enterprise network and a control zone. Requirements cover mutual authentication, least privilege, session control, logging and safe loss of connectivity. The product supplier provides secure update capability; the integrator configures it; the asset owner governs accounts and monitors use.
Build evidence that explains the reasoning.
Roles, lifecycle, risk decisions and governance.
Assets, boundaries and permitted communications.
System, component and operational controls.
Threats, coding, verification, vulnerabilities and updates.
Configured identities, access paths and failure behaviour.
Accounts, monitoring, patches and incident response.
Common failure patterns
Assets are listed without architecture or trust boundaries.
A level is quoted without target context and system allocation.
Asset-owner and integrator responsibilities are omitted.
Monitoring, testing, deployment and recovery are undefined.
Further learning
- ISA / IEC 62443 seriesOfficial ISA overview of the industrial cybersecurity standards family.
- TEA-110 · Secure embedded developmentThreat modelling, trusted foundations and update strategy.
Use the standard to strengthen decisions, not decorate them.
Make scope, tailoring, responsibilities, technical reasoning and objective evidence explicit—and always work from the current authorised text.