IEC 62443 — Industrial Communication Networks: Network and System Security
IEC 62443 is the global standard series for securing Industrial Automation and Control Systems (IACS). Part 3-3 defines system security requirements organized around 7 Foundational Requirements, each assessed across 4 Security Levels. The standard addresses the complete lifecycle of industrial cybersecurity, from risk assessment through zones and conduits to ongoing monitoring.
7
Foundational Requirements
4
Security Levels
14
Standard Parts
Global
Adoption
User, device, and software identity verification with multi-factor support at higher security levels. Applies to all IACS components.
Role-based access control and least privilege enforcement for OT operators, maintenance personnel, and automated processes.
Communication integrity verification, malicious code protection, data-at-rest and in-transit encryption for control system data.
Network segmentation via zones and conduits, application partitioning, and boundary protection between security zones.
Audit logging, incident response, denial of service protection, backup and recovery for operational continuity.
Identify all IACS assets and define security zones and conduits based on operational requirements and risk.
Determine the required Security Level Target (SL-T) for each zone based on threat analysis and risk tolerance.
Compare current Security Level Capability (SL-C) against the target SL-T to identify control gaps.
Apply System Requirements (SRs) and Requirement Enhancements (REs) to close gaps per each Foundational Requirement.
Test control effectiveness through penetration testing of zone boundaries and security level verification.
Ongoing surveillance, periodic reassessment, and change management to maintain achieved security levels.