Overview
IEC 62443-3-2:2020 is part of the IEC 62443 series for security for industrial automation and control systems (IACS). It defines a structured security risk assessment for system design, focused on the System Under Consideration (SUC). The standard prescribes how to partition an SUC into zones and conduits, assess risks per zone/conduit, set target security levels (SL‑T), and document security requirements for procurement, engineering and compliance.
Key Topics and Requirements
- Define the SUC: identify the SUC perimeter, access points and operating environment.
- Zones and conduits: partition the SUC into logical/physical zones and the conduits (communication groupings) that connect them.
- Initial and detailed risk assessment: perform an initial cyber security risk assessment and, for each zone/conduit, conduct a detailed workflow that includes:
- identifying threats and vulnerabilities,
- determining consequences and impacts,
- estimating likelihood,
- calculating unmitigated and residual risk,
- comparing risk to tolerable risk,
- identifying existing and additional countermeasures.
- Determine SL‑T: establish the target security level for each zone/conduit to align design decisions with required capabilities.
- Documentation and approval: produce a cyber security requirements specification, zone/conduit drawings and characteristics, threat/environment assumptions, and obtain asset owner approval.
- Supporting material: the standard contains workflow diagrams, annexes with example risk matrices and guidance on security levels.
Practical Applications
IEC 62443-3-2 is applied during the design and engineering phases of industrial control systems to ensure security is built into system architecture. Typical uses:
- Security architecture design for SCADA, DCS and other IACS deployments.
- Supplier and system integrator scoping of security requirements during procurement and projects.
- Asset owner risk management and compliance evidence for audits and regulators.
- Aligning technical countermeasures with required SL‑T and with product/system capabilities.
Who uses it:
- Asset owners, engineering teams and OT security professionals.
- System integrators and product suppliers designing or delivering IACS.
- Service providers performing risk assessments and security testing.
- Compliance authorities and auditors assessing adequacy of system design.
Related Standards
- IEC 62443-3-3: aligns SL‑T with system security requirements and SL‑C capability levels.
- IEC TS 62443‑1‑1: introduces the zones and conduits concept referenced in 3‑2.
Keywords: IEC 62443-3-2, industrial automation security, IACS risk assessment, zones and conduits, SL-T, OT cybersecurity, system design risk assessment.