
Explore the ISA-IEC 62443 standard to secure industrial automation and control systems through a risk-based lifecycle, addressing safety, reliability, integrity, and security.
Explore the ISA-IEC 62443 series, its four groups, and key concepts, glossary terms, risk assessment, and security lifecycle for IACS.
Identify and partition the industrial control system into zones to define common security requirements, assess risk, and implement threat modeling that guides cybersecurity safeguards within the ISA-IEC 62443 framework.
Explore how ISA-IEC 62443 defines security levels: capability, target, and achieve, and how identity, access control, integrity, confidentiality, data flow, incident management, and availability shape them.
Explore seven isa-iec 62443 requirements, including identification and authentication control, use control, system integrity, data confidentiality with encryption and ssl, data flow with network segmentation, timely incident response, and availability.
Explore the ISA-IEC 62443 maturity model, comparing initial to optimized levels, and show how policies, processes, and people establish measurable security across industrial automation and control systems.
Introduce the ISA-IEC 62443 IACS environment and its components. Explain security by design, defense in depth, essential functions, and the roles of maintenance, integration, product providers, and risk assessment.
Map and extend your existing cybersecurity program to ISA-IEC 62443, establishing governance, risk management, asset inventory, and incident response for holistic industrial control system security.
Explore how ISA-IEC 62443 security level 1 protects industrial automation through enterprise-network and control-zone segmentation, authentication, firewall use, and audit trails.
Presents an example of ISA-IEC 62443 security level 2, detailing certificate-based authentication, centralized access control, intrusion detection, network segmentation, and secure remote access via VPN and firewalls.
explores ISA-IEC 62443 security level 3 for control systems, emphasizing centralized account management, certificate authority authentication, and hardware security, plus wireless threat detection and audit trails.
What is ISA &IEC?
Initially, the ISA99 committee considered IT standards and practices for use in the IACS. However, it was soon found that this was not sufficient to ensure the safety, integrity, reliability, and security of an IACS.
The International Society of Automation (ISA) and the International Electrotechnical Commission (IEC) have joined forces to address the need to improve the cybersecurity of IACS.
Why to Secure IACS?
IACS are physical-cyber systems, the impact of a cyberattack could be severe. The consequences of a cyberattack on an IACS include, but are not limited to:
Endangerment of public or employee safety or health
Damage to the environment
Damage to the Equipment Under Control
Loss of product integrity
Loss of public confidence or company reputation
Violation of legal or regulatory requirements
Loss of proprietary or confidential information
Financial loss
Impact on entity, local, state, or national security
How to Secure IACS?
Risk Assessment
Security Level
Maturity Level
Design Principle
Foundational Requirements (FRs) form the basis for technical requirements throughout the
ISA/IEC 62443 Series. All aspects associated with meeting a desired IACS security level (people, processes, and technology) are derived through meeting the requirements associated with the
seven following Foundational Requirements:
o FR 1 – Identification and Authentication Control (IAC)
o FR 2 – Use Control (UC)
o FR 3 – System Integrity (SI)
o FR 4 – Data Confidentiality (DC)
o FR 5 – Restricted Data Flow (RDF)
o FR 6 – Timely Response to Events (TRE)
o FR 7 – Resource Availability (RA)