Quick Facts
Foundations
How to Use This Guide
- 1
Skim the Quick Facts panel first. The core vocabulary line โ Zones, Conduits, Security Levels โ is what every other section on this page keeps coming back to.
- 2
Read Section 03 before the standard's structure. Seeing how 62443 differs from SP 800-82, ATT&CK for ICS, and CIP-008 makes the three-audience organization in Section 04 easier to place.
- 3
In Section 04, read the Security Levels table and the seven Foundational Requirements before the four series cards. That vocabulary is what every part of the standard is actually built from โ the series structure is just where each piece of it lives.
- 4
Treat Section 05 as a lookup, not a read-through. Come back to it whenever a term โ SL-T versus SL-A, or "conduit" versus "zone" โ needs a precise definition.
- 5
If you're prepping to teach, start at Section 08. The Zones & Conduits Redraw exercise is the one that most reliably makes the whole standard click.
Positioning: IEC 62443 vs. the Other Core Frameworks
NIST SP 800-82 borrows IEC 62443's segmentation ideas rather than replacing them. ATT&CK for ICS documents what attackers actually do to systems that weren't built this way. CIP-008 governs what happens legally once one of those attacks becomes an incident. IEC 62443 is the one framework in the set that answers "how do you design and build this correctly in the first place, and can you prove it?"
| Attribute | ISA/IEC 62443 | SP 800-82 / ATT&CK for ICS / CIP-008 |
|---|---|---|
| Type | Certifiable design standard, written for control systems | Federal risk guidance, threat-intel knowledge base, or mandatory sector regulation |
| Origin / Authority | ISA99 committee, jointly published with IEC (IEC TC65/WG10) | NIST (U.S. federal), MITRE (federally funded R&D), NERC (the ERO, under FERC) |
| Primary Question | "How do you design and build a secure IACS, and can you prove it?" | "How do you manage OT risk?", "What has been done to systems like this?", or "What must you legally report?" |
| Enforcement | Voluntary, but formally certifiable through ISASecure | Federal requirement (800-82), none (ATT&CK for ICS), or legal penalty (CIP-008) |
| Typical Pairing | Supplies the design vocabulary โ zones, conduits, security levels โ the others build on or defend | 800-82 reinforces the same segmentation ideas; ATT&CK for ICS shows what happens when it's missing; CIP-008 is what you report against once it fails |
Security Levels, Requirements & the Four Series
Two pieces of vocabulary โ Security Levels and the seven Foundational Requirements โ cut across the entire standard and get defined before anything else. Everything after that lives in one of four series, organized by the audience it's written for. The stage colors below reuse this site's existing strand colors: General borrows the orange used for "Foundations," Policies & Procedures borrows the green used for "Operations," System borrows the blue used for "Protocols," and Component borrows the indigo used for "Dev Tools."
Security Levels at a Glance
| Level | Protects Against |
|---|---|
| SL 0 | No specific protection required |
| SL 1 | Casual or coincidental violation |
| SL 2 | Intentional violation using simple means, low resources, generic skills, low motivation |
| SL 3 | Intentional violation using sophisticated means, moderate resources, IACS-specific skills, moderate motivation |
| SL 4 | Intentional violation using sophisticated means, extended resources, IACS-specific skills, high motivation โ nation-state level |
A zone or component can carry three different SL values: SL-T (Target โ what it should achieve), SL-C (Capability โ what a product is inherently capable of), and SL-A (Achieved โ what's actually in place today). Most real audit findings are a gap between SL-T and SL-A.
The Seven Foundational Requirements
The Four Series
Concepts & Terminology
Policies & Procedures
System
Component
Series 1-x โ General
Series 2-x โ Policies & Procedures (Asset Owner)
Series 3-x โ System (Integrator)
Series 4-x โ Component (Product Supplier)
Definitions & Scope
These terms recur across every series of the standard โ students who are shaky on them will misapply the security-level table above almost immediately.
IACS
Industrial Automation and Control Systems โ the full scope of personnel, hardware, software, and policies involved in operating and securing an industrial process.
Zone
A grouping of logical or physical assets that share common security requirements โ the unit everything else in the standard is assigned to.
Conduit
The network path connecting two zones, which itself carries its own security requirements โ segmentation made explicit and documented rather than assumed.
SL-T / SL-C / SL-A
Target, Capability, and Achieved Security Level โ what a zone should reach, what a product can inherently support, and what's actually in place today.
Asset Owner
The organization that operates the IACS day to day โ the audience for the 2-x series.
System Integrator
The organization that designs and deploys the IACS on the asset owner's behalf โ the audience for the 3-x series.
Product Supplier
The vendor that manufactures the PLCs, HMIs, and network components used in the system โ the audience for the 4-x series.
Compensating Countermeasure
An alternative safeguard used when a specified requirement can't be implemented directly โ the standard's own version of the compensating-control concept used across CIP-008 and SP 800-82.
Related Resources
62443 sits inside a small ecosystem of committees, certification bodies, and complementary standards that are usually referenced alongside it.
| Resource | Focus | How It Connects to 62443 |
|---|---|---|
| ISASecure | Third-party certification scheme | Certifies products against 4-1/4-2 and asset-owner security programs against 2-x โ the practical proof-of-conformance layer |
| ISA Global Cybersecurity Alliance | Industry alliance | Publishes implementation guidance, training, and case studies built around the series |
| IEC TC65/WG10 | Joint standards committee | Co-develops and formally maintains the series alongside ISA99 |
| NIST SP 800-82 | Complementary federal guidance | Explicitly written to be compatible with 62443's zones-and-conduits model rather than competing with it |
| ISO/IEC 27001 | General IT security management systems | The certifiable ISMS standard that 62443-2-1's asset-owner program structure loosely mirrors |
Certification & Practical Use
Nobody is legally required to adopt 62443 the way NERC entities must adopt CIP-008 โ but unlike ATT&CK for ICS, there is something concrete to certify against, and the industry actually uses that option.
Product Certification
Vendors certify individual components against 4-1 (process) and 4-2 (technical requirements) through ISASecure, giving buyers a verifiable claim instead of a marketing one.
Asset Owner Programs
Plants assess or certify their security program against 2-1 and 2-4, turning "we take security seriously" into an auditable statement.
System Integrator Practice
Integrators design to 3-2 and 3-3 even without seeking formal certification, and cite that alignment directly in proposals and RFP responses.
Procurement Language
Buyers write a target Security Level directly into purchase contracts โ making 62443 the shared vocabulary a plant and a vendor use to negotiate what "secure enough" actually means.
๐ Teaching Note
Anchor lesson: Lesson 2 (Purdue Model) and Lesson 8 (Frameworks for OT Security). The Purdue model your students already know is the easiest bridge into zones and conduits โ every Purdue level is a candidate zone boundary.
Classroom Uses
Zones & Conduits Redraw
Take the Purdue-model diagram from Lesson 2, redraw it as zones and conduits, and assign a Target Security Level to each zone with a written justification tied to attacker capability, not perceived importance.
FR Coverage Audit
Given a fictional plant's existing controls, students map each control to one of the seven Foundational Requirements and identify which FRs have zero coverage.
Component Certification Review
Students review a fictional vendor datasheet's conformance claims against 4-1/4-2 and decide whether it actually supports the SL-T assigned to the zone it would sit in.
Cross-Framework Bridge
Take the same zone/SL assignments and map them to the SP 800-53 overlay controls from the NIST SP 800-82 page's Overlay Tailoring Drill, showing where the two frameworks reinforce each other.
Sources & Further Reading
- ISA โ ISA/IEC 62443 Series of StandardsOfficial series overview and part-by-part breakdown from the standards developer
- ISA Global Cybersecurity AllianceImplementation guidance, training, and case studies built around the 62443 series
- ISASecure CertificationThird-party certification scheme for products, processes, and systems against 62443
This page is a teaching summary of a publicly available standard series, not a reproduction of its copyrighted text. Specific part numbers, requirement text, and certification scope should be verified against the current official ISA/IEC 62443 publications before use in coursework โ per this course's own Safeguards policy on faculty review of generated content.