OT

Teaching Operational Technologies

Core Frameworks โ€” Student Guide

โ† Course Navigation
Design Standard ยท Certifiable

ISA/IEC 62443 โ€” Industrial Automation & Control Systems Security

A student's walk-through of the only certifiable, control-engineer-written standard in this course's Core Frameworks set โ€” its zones-and-conduits vocabulary, its security levels, its four-series structure, and how to teach it.

โ† Back to Course Navigation

Quick Facts

Type
Certifiable design standard series
Publisher
ISA / IEC (jointly, IEC TC65/WG10)
Structure
Four series: 1-x, 2-x, 3-x, 4-x
Core Vocabulary
Zones, Conduits, Security Levels 0โ€“4
Certification
ISASecure โ€” products, processes & systems
Primary Use
Segmentation architecture & procurement language
01

Foundations

02

How to Use This Guide

  1. 1

    Skim the Quick Facts panel first. The core vocabulary line โ€” Zones, Conduits, Security Levels โ€” is what every other section on this page keeps coming back to.

  2. 2

    Read Section 03 before the standard's structure. Seeing how 62443 differs from SP 800-82, ATT&CK for ICS, and CIP-008 makes the three-audience organization in Section 04 easier to place.

  3. 3

    In Section 04, read the Security Levels table and the seven Foundational Requirements before the four series cards. That vocabulary is what every part of the standard is actually built from โ€” the series structure is just where each piece of it lives.

  4. 4

    Treat Section 05 as a lookup, not a read-through. Come back to it whenever a term โ€” SL-T versus SL-A, or "conduit" versus "zone" โ€” needs a precise definition.

  5. 5

    If you're prepping to teach, start at Section 08. The Zones & Conduits Redraw exercise is the one that most reliably makes the whole standard click.

03

Positioning: IEC 62443 vs. the Other Core Frameworks

NIST SP 800-82 borrows IEC 62443's segmentation ideas rather than replacing them. ATT&CK for ICS documents what attackers actually do to systems that weren't built this way. CIP-008 governs what happens legally once one of those attacks becomes an incident. IEC 62443 is the one framework in the set that answers "how do you design and build this correctly in the first place, and can you prove it?"

AttributeISA/IEC 62443SP 800-82 / ATT&CK for ICS / CIP-008
TypeCertifiable design standard, written for control systemsFederal risk guidance, threat-intel knowledge base, or mandatory sector regulation
Origin / AuthorityISA99 committee, jointly published with IEC (IEC TC65/WG10)NIST (U.S. federal), MITRE (federally funded R&D), NERC (the ERO, under FERC)
Primary Question"How do you design and build a secure IACS, and can you prove it?""How do you manage OT risk?", "What has been done to systems like this?", or "What must you legally report?"
EnforcementVoluntary, but formally certifiable through ISASecureFederal requirement (800-82), none (ATT&CK for ICS), or legal penalty (CIP-008)
Typical PairingSupplies the design vocabulary โ€” zones, conduits, security levels โ€” the others build on or defend800-82 reinforces the same segmentation ideas; ATT&CK for ICS shows what happens when it's missing; CIP-008 is what you report against once it fails
04

Security Levels, Requirements & the Four Series

Two pieces of vocabulary โ€” Security Levels and the seven Foundational Requirements โ€” cut across the entire standard and get defined before anything else. Everything after that lives in one of four series, organized by the audience it's written for. The stage colors below reuse this site's existing strand colors: General borrows the orange used for "Foundations," Policies & Procedures borrows the green used for "Operations," System borrows the blue used for "Protocols," and Component borrows the indigo used for "Dev Tools."

Security Levels at a Glance

LevelProtects Against
SL 0No specific protection required
SL 1Casual or coincidental violation
SL 2Intentional violation using simple means, low resources, generic skills, low motivation
SL 3Intentional violation using sophisticated means, moderate resources, IACS-specific skills, moderate motivation
SL 4Intentional violation using sophisticated means, extended resources, IACS-specific skills, high motivation โ€” nation-state level

A zone or component can carry three different SL values: SL-T (Target โ€” what it should achieve), SL-C (Capability โ€” what a product is inherently capable of), and SL-A (Achieved โ€” what's actually in place today). Most real audit findings are a gap between SL-T and SL-A.

The Seven Foundational Requirements

The Four Series

1-xGeneral
Concepts & Terminology
Defines zones, conduits, security levels, and the shared vocabulary every other part of the standard uses.
2-xAsset Owner
Policies & Procedures
Security program requirements for the organization that operates the plant, and for the service providers it hires.
3-xIntegrator
System
Risk assessment for system design and the security requirements mapped to each Security Level.
4-xProduct Supplier
Component
Secure development lifecycle and technical security requirements for the individual products that get built.

Series 1-x โ€” General

Series 2-x โ€” Policies & Procedures (Asset Owner)

Series 3-x โ€” System (Integrator)

Series 4-x โ€” Component (Product Supplier)

05

Definitions & Scope

These terms recur across every series of the standard โ€” students who are shaky on them will misapply the security-level table above almost immediately.

IACS

Industrial Automation and Control Systems โ€” the full scope of personnel, hardware, software, and policies involved in operating and securing an industrial process.

Zone

A grouping of logical or physical assets that share common security requirements โ€” the unit everything else in the standard is assigned to.

Conduit

The network path connecting two zones, which itself carries its own security requirements โ€” segmentation made explicit and documented rather than assumed.

SL-T / SL-C / SL-A

Target, Capability, and Achieved Security Level โ€” what a zone should reach, what a product can inherently support, and what's actually in place today.

Asset Owner

The organization that operates the IACS day to day โ€” the audience for the 2-x series.

System Integrator

The organization that designs and deploys the IACS on the asset owner's behalf โ€” the audience for the 3-x series.

Product Supplier

The vendor that manufactures the PLCs, HMIs, and network components used in the system โ€” the audience for the 4-x series.

Compensating Countermeasure

An alternative safeguard used when a specified requirement can't be implemented directly โ€” the standard's own version of the compensating-control concept used across CIP-008 and SP 800-82.

06

Related Resources

62443 sits inside a small ecosystem of committees, certification bodies, and complementary standards that are usually referenced alongside it.

ResourceFocusHow It Connects to 62443
ISASecureThird-party certification schemeCertifies products against 4-1/4-2 and asset-owner security programs against 2-x โ€” the practical proof-of-conformance layer
ISA Global Cybersecurity AllianceIndustry alliancePublishes implementation guidance, training, and case studies built around the series
IEC TC65/WG10Joint standards committeeCo-develops and formally maintains the series alongside ISA99
NIST SP 800-82Complementary federal guidanceExplicitly written to be compatible with 62443's zones-and-conduits model rather than competing with it
ISO/IEC 27001General IT security management systemsThe certifiable ISMS standard that 62443-2-1's asset-owner program structure loosely mirrors
07

Certification & Practical Use

Nobody is legally required to adopt 62443 the way NERC entities must adopt CIP-008 โ€” but unlike ATT&CK for ICS, there is something concrete to certify against, and the industry actually uses that option.

Product Certification

Vendors certify individual components against 4-1 (process) and 4-2 (technical requirements) through ISASecure, giving buyers a verifiable claim instead of a marketing one.

Asset Owner Programs

Plants assess or certify their security program against 2-1 and 2-4, turning "we take security seriously" into an auditable statement.

System Integrator Practice

Integrators design to 3-2 and 3-3 even without seeking formal certification, and cite that alignment directly in proposals and RFP responses.

Procurement Language

Buyers write a target Security Level directly into purchase contracts โ€” making 62443 the shared vocabulary a plant and a vendor use to negotiate what "secure enough" actually means.

๐Ÿ“– Teaching Note

Anchor lesson: Lesson 2 (Purdue Model) and Lesson 8 (Frameworks for OT Security). The Purdue model your students already know is the easiest bridge into zones and conduits โ€” every Purdue level is a candidate zone boundary.

08

Classroom Uses

Zones & Conduits Redraw

Take the Purdue-model diagram from Lesson 2, redraw it as zones and conduits, and assign a Target Security Level to each zone with a written justification tied to attacker capability, not perceived importance.

FR Coverage Audit

Given a fictional plant's existing controls, students map each control to one of the seven Foundational Requirements and identify which FRs have zero coverage.

Component Certification Review

Students review a fictional vendor datasheet's conformance claims against 4-1/4-2 and decide whether it actually supports the SL-T assigned to the zone it would sit in.

Cross-Framework Bridge

Take the same zone/SL assignments and map them to the SP 800-53 overlay controls from the NIST SP 800-82 page's Overlay Tailoring Drill, showing where the two frameworks reinforce each other.

09

Sources & Further Reading

This page is a teaching summary of a publicly available standard series, not a reproduction of its copyrighted text. Specific part numbers, requirement text, and certification scope should be verified against the current official ISA/IEC 62443 publications before use in coursework โ€” per this course's own Safeguards policy on faculty review of generated content.