Where IEC 62443 Fits
IEC 62443 is the international series of standards for securing industrial automation and control systems (IACS): the SCADA, DCS, PLCs, RTUs and networks that run physical processes. Unlike ISO 27001, it doesn't treat security as one organisation's problem. It splits responsibilities between the asset owner who operates the system, the service provider who integrates and maintains it, and the product supplier who builds the components, and gives each of them their own requirements.
No Australian law requires IEC 62443 by name, but it is the most widely used reference for OT security requirements, and it fits alongside the SOCI Act's risk management program rules and the AESCSF. I also keep a free, plain-English guide to the whole series at iec62443.au.
How I Help
Asset owners: a security program for your OT
Building or reviewing a cybersecurity management system (CSMS) to IEC 62443-2-1, the OT counterpart of an ISO 27001 ISMS: policies, roles, asset inventory, risk assessment, patch management (IEC 62443-2-3), change control, incident response, and the governance that keeps it running. Where you already have an ISMS, I extend it into OT rather than building a second, competing system.
Risk assessment, zones and conduits (IEC 62443-3-2)
Partitioning your system into zones and conduits, assessing the risk of each, and setting a target security level (SL-T) that justifies the controls you spend money on. See OT cybersecurity risk assessments for how an assessment runs. I draw the models in design.iec62443.au, a free zone and conduit designer I built for this work.
System requirements and design (IEC 62443-3-3)
Turning each SL-T into concrete system requirements and requirement enhancements for a new system or an upgrade, reviewing designs against them, and writing them into a cybersecurity requirements specification your integrator can price and build to.
Integrators and service providers (IEC 62443-2-4)
For asset owners: setting and checking the security capabilities you expect from integrators and maintenance contractors, from secure remote access to hand-over documentation. For integrators: understanding what your clients will ask of you under IEC 62443-2-4, and building it into the way you deliver.
Rail and transport (CLC/TS 50701)
For railway projects, the same zone and conduit approach applied through CLC/TS 50701, the railway cybersecurity specification built on IEC 62443.
A Typical IEC 62443 Engagement
Most asset-owner engagements follow the IEC 62443-3-2 workflow, then carry the results through design and into operation.
-
Define the system under consideration
What is in scope, what isn't, and every interface that crosses the boundary, including vendor remote access and links to corporate IT.
-
Initial risk assessment
The worst credible consequences if the system were compromised: safety, environment, service to customers, regulatory and financial.
-
Zones and conduits
Assets grouped by function, criticality and location, with the conduits between them and what is allowed to cross each one.
-
Detailed risk assessment and SL-T
Threats, vulnerabilities and existing countermeasures for each zone, compared with your tolerable risk to set a target security level.
-
Cybersecurity requirements
The IEC 62443-3-3 requirements for each zone at its SL-T, compensating countermeasures where a requirement can't be met, and the assumptions behind them.
-
Implement, verify and accept
Design reviews, security testing at FAT and SAT, and documented residual risk for the asset owner to accept.
-
Operate and sustain
Patching, backups, change control, monitoring and periodic reassessment under your CSMS, so the security level you paid for doesn't erode.
Security Levels in Brief
IEC 62443 defines security levels by the attacker a zone has to withstand, not by how many controls it has.
SL 1
Protection against casual or coincidental violation, such as a mistake or misuse.
SL 2
Protection against intentional attack using simple means, with low resources, generic skills and low motivation.
SL 3
Protection against intentional attack using sophisticated means, with moderate resources, IACS-specific skills and moderate motivation.
SL 4
Protection against intentional attack using sophisticated means, with extended resources, IACS-specific skills and high motivation.
Each zone is given a target (SL-T); systems and components have a capability (SL-C); and what is actually installed achieves SL-A. The requirements sit under seven foundational requirements: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability.
IEC 62443 and Australian Obligations
IEC 62443 isn't one of the cyber frameworks named in the SOCI Act's risk management program rules. A common approach is to report against a named framework (often the AESCSF in energy, or the Essential Eight and ISO 27001 for the corporate network) and use IEC 62443 to design and justify the OT controls behind it. One well-mapped set of controls then satisfies both. See SOCI Act compliance for OT and AESCSF assessments.
Frequently Asked Questions
Is IEC 62443 mandatory in Australia?
No Australian law requires IEC 62443 by name. The SOCI Act's critical infrastructure risk management program (CIRMP) rules require a recognised cyber framework, such as the AESCSF, the NIST Cybersecurity Framework, ISO/IEC 27001 or the Essential Eight, and IEC 62443 is commonly used alongside it to design the OT controls. Asset owners can also make IEC 62443 a contractual requirement for their integrators and suppliers.
What is the difference between IEC 62443 and ISO 27001?
ISO/IEC 27001 specifies an information security management system for an organisation and is technology-neutral. IEC 62443 is written for industrial automation and control systems: it adds technical requirements for systems and components, security levels based on the attacker, and separate obligations for asset owners, service providers and product suppliers. Many organisations use ISO 27001 for corporate IT and IEC 62443 for OT under one governance structure.
What is an ISA/IEC 62443 Cybersecurity Expert?
It is the highest designation in ISA's IEC 62443 certificate program, awarded to people who have passed all four specialist certificates: Cybersecurity Fundamentals, Risk Assessment, Design, and Maintenance.
Can you certify our system to IEC 62443?
No. Formal certification is issued by accredited certification bodies, such as those operating the ISASecure schemes. I help asset owners and integrators meet the requirements and assemble the evidence; I don't issue certificates.
Do you only work in Brisbane?
No. I'm based in Brisbane and work Australia-wide, on site or remotely, and with overseas clients where the work suits remote delivery.
Related Services
- OT Cybersecurity Risk AssessmentAn IEC 62443-3-2 assessment of your SCADA and control systems, safe for live plant.
- SOCI Act & CIRMP for OTBring SCADA and control systems properly into your critical infrastructure risk management program.
- AESCSF AssessmentsFacilitated AESCSF self-assessments and uplift plans for electricity and gas operators.
- IT & OT/ICS CybersecurityThe full cybersecurity service: management systems, compliance, risk, architecture and training.
Discuss Your IEC 62443 Project
Whether you are starting from scratch or want a second opinion on an existing program, a short scoping call is the best first step.