Lesson Overview
Orientation, anchoring analogy, and what you should be able to do by the end.
Faculty who start building an OT security course almost always hit the same wall: there are four widely cited bodies of guidance — IEC 62443, NIST SP 800-82, the NIST Cybersecurity Framework (CSF), and ISO/IEC 27001 — and they all sound authoritative, they all use overlapping vocabulary, and none of them announces which one a course should be built around. The usual result is a syllabus that samples all four, confuses students, and produces graduates who can name standards but cannot apply one.
This lesson takes the opposite approach. We treat the four documents as tools with different jobs, learn the internal logic of the one that is genuinely OT-native (IEC 62443), and then use the others as supporting material rather than competing curricula. By the end you will have drafted a one-page crosswalk you can hand to your own students.
Think about constructing a hospital. The zoning ordinance decides what may be built where and how areas are separated — that is IEC 62443, which partitions a plant into zones and controls what crosses between them. The engineering handbook for that specific building type gives detailed, sector-aware practice notes — that is NIST SP 800-82. The executive summary the hospital board reads, written so a non-engineer can ask sensible questions about risk, is NIST CSF. And the accreditation program that audits whether the hospital runs a disciplined management system, with documented policies and internal reviews, is ISO/IEC 27001.
All four describe the same hospital. Only one of them tells the contractor where to put the walls. Hold onto that distinction — it drives every decision in this lesson.
Learning objectives
By the end of this 4-hour session, you will be able to:
- Explain the scope, intended audience, and structure of IEC 62443, NIST SP 800-82 Rev. 3, NIST CSF 2.0, and ISO/IEC 27001, and state the job each one does best.
- Identify zones and conduits in a given plant network description and justify each boundary in terms of shared risk and required communication.
- Differentiate target, capability, and achieved Security Levels (SL-T, SL-C, SL-A) and assign an SL-T to a zone with written rationale.
- Compare the four frameworks across scope, unit of analysis, certification pathway, and classroom usability using a structured comparison.
- Evaluate which framework should serve as the spine of a specific course, given a program's constraints, and defend the choice.
- Design a one-page student-facing framework crosswalk that maps supporting standards onto your chosen spine.
1. The Landscape: Why There Are Four
Different authors, different customers, different units of analysis.
The four documents exist because four different communities needed something. Understanding who wrote each one and for whom resolves most of the apparent conflict between them.
- IEC 62443 is a multi-part series developed through ISA99 and published jointly by ISA and the IEC. Its customer is the industrial automation and control system (IACS) community: asset owners, system integrators, and product suppliers. Its unit of analysis is the system under consideration (SUC) — a defined piece of a plant — broken into zones and conduits.
- NIST SP 800-82 is a U.S. federal special publication, now in Revision 3 (2023), titled Guide to Operational Technology (OT) Security. Its customer is anyone who has to apply general-purpose security controls (NIST SP 800-53) to OT without breaking the process. Its unit of analysis is the control overlay: which of the general controls apply, how they must be tailored, and what to do when they cannot be applied.
- NIST CSF, now at version 2.0 (2024), is not a control catalog at all. It is an outcome-based common language organized into six Functions: Govern, Identify, Protect, Detect, Respond, Recover. Its customer is leadership and cross-organizational communication. Its unit of analysis is the outcome ("Assets are managed consistently with their criticality"), deliberately silent on how you achieve it.
- ISO/IEC 27001 is a certifiable international standard for an Information Security Management System (ISMS). Its customer is an organization that must demonstrate governance discipline to auditors, insurers, or trading partners. Its unit of analysis is the management system: scope, risk process, Statement of Applicability, internal audit, management review.
2. IEC 62443: Zones and Conduits
The core structural idea of the whole series, and the one worth teaching first.
A zone is a grouping of logical or physical assets that share common security requirements. A conduit is the controlled communication path between zones — and critically, a conduit is itself a special kind of zone whose only members are the communication assets. Partitioning happens in IEC 62443-3-2, which defines the risk assessment process; the technical requirements those zones then inherit live in IEC 62443-3-3 (system requirements) and IEC 62443-4-2 (component requirements).
Two rules drive nearly every partitioning decision students will make:
- Group by shared risk, not by network topology. Two devices on the same VLAN may belong in different zones if their consequence of compromise differs sharply.
- Separate assets performing safety functions. IEC 62443-3-2 requires that safety-related assets be placed in a zone separate from non-safety assets. A safety instrumented system does not share a zone with basic process control just because they sit in the same cabinet.
A ship is not one hollow hull. It is divided into watertight compartments so a breach in one does not sink the vessel, and the openings between compartments are deliberate, few, and closable. Zones are compartments. Conduits are the hatches. The security question is never "is the hull strong?" but "if this compartment floods, what else floods with it, and can I close the hatch in time?"
Worked example — Meridian Water District, Pump Station 4
A fictional municipal water utility operates a pump station with the following assets. Read it the way an assessor would: consequence first, wiring second.
| Asset tag | Description | Communications | Consequence of compromise |
|---|---|---|---|
| PLC-401 | Allen-Bradley-class controller, lead/lag pump sequencing | EtherNet/IP to HMI; Modbus/TCP to VFDs | Loss of pressure to 4,000 service connections |
| HMI-401 | Operator workstation, Windows-based, local to station | EtherNet/IP to PLC-401; historian feed northbound | Operator blindness; possible unsafe manual commands |
| VFD-401A/B | Variable frequency drives, 150 hp pumps | Modbus/TCP, register-level control | Mechanical damage, water hammer |
| SIS-401 | Safety controller: over-pressure trip and dry-run protection | Hardwired trip; read-only diagnostics over serial gateway | Pipe rupture, pump destruction, potential injury |
| HIST-CORP | Plant historian, corporate data center | OPC UA northbound to business analytics | Loss of reporting; no direct process impact |
| RTU-VENDOR | Cellular RTU used by the pump vendor for remote diagnostics | DNP3 over vendor-managed cellular link | Third-party path into the control network |
A defensible partition looks like this. Note that SIS-401 gets its own zone even though it lives in the same building, and that the vendor's cellular RTU is not allowed to be "just another device on the control LAN":
3. Security Levels: SL-T, SL-C, and SL-A
The most misunderstood idea in 62443 — and the most testable.
A Security Level in IEC 62443 is not a maturity score for an organization. It is a statement about the capability of an adversary that a zone or component is expected to withstand, expressed on a 0-to-4 scale and evaluated against seven foundational requirements (FR 1 through FR 7): identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability.
| Level | Protects against | Adversary profile | Plausible plant example |
|---|---|---|---|
| SL 0 | No specific requirement | None stated | An isolated display with no consequence of compromise |
| SL 1 | Casual or coincidental violation | An untrained person clicking the wrong thing | A conference-room dashboard on a read-only feed |
| SL 2 | Intentional violation using simple means | Low resources, generic skills, low motivation | Supervisory HMI zone; operations DMZ |
| SL 3 | Intentional violation using sophisticated means | Moderate resources, IACS-specific skills, moderate motivation | Control zone with pump PLC; safety zone |
| SL 4 | Intentional violation using sophisticated means with extended resources | Extended resources, IACS-specific skills, high motivation | National-scale transmission or nuclear-adjacent systems |
The three flavours students confuse
Each card is a button: press Enter or Space to flip it. All four definitions also print in full.
Worked example — reading an SL gap
Back at Pump Station 4, the assessment team sets SL-T 3 for the Control Zone. They then inventory what is actually installed:
- PLC-401 ships with SL-C 2 for FR 1 (identification and authentication control) — it supports a single shared engineering password, not per-user accounts.
- The VFDs accept unauthenticated Modbus/TCP writes to their speed-reference registers. Modbus/TCP has no authentication in the protocol at all, so FR 1 capability at the component level is effectively SL-C 0.
- The zone therefore achieves roughly SL-A 1 for FR 1 against a target of SL 3.
The gap is not closed by buying a firewall and declaring victory. Realistic compensating measures, in the order an engineer would consider them, are: move VFD control behind the PLC so no supervisory device writes Modbus registers directly; enforce per-user authentication at the conduit through a brokered jump host; and add monitoring that alarms on any Modbus write function code (function 6 or 16) originating outside the Control Zone. Documenting the residual gap is itself a valid outcome — 62443 expects an assessment record, not a perfect score.
4. NIST SP 800-82 Rev. 3 and the Cybersecurity Framework
One tailors controls for OT; the other gives everyone a shared vocabulary.
NIST SP 800-82 Revision 3
Revision 3 broadened the title from "Industrial Control Systems" to "Operational Technology," reflecting that building automation, physical access control, and transportation systems face the same problem as a refinery. Its most classroom-useful contribution is the OT overlay: for each control family in NIST SP 800-53, it states whether the control applies to OT, how it must be tailored, and what compensating control to use when the standard approach would endanger the process.
If IEC 62443 is the zoning ordinance, SP 800-82 is the annotated field guide an experienced engineer hands you on your first day: "Yes, the corporate policy says patch within 30 days. Here is what that actually means when the vendor will void your safety certification and the next maintenance window is in eight months."
Worked example. Corporate policy mandates automatic screen lock after 10 minutes of inactivity. Applied literally to HMI-401 at Pump Station 4, an operator watching a developing over-pressure condition loses the screen at the worst moment. The SP 800-82 tailoring pattern is: keep the control's intent (prevent unauthorized use of an unattended console), change the implementation (physical access control to the operator room, session lock on the engineering workstation but not the alarm display, and camera coverage), and document the deviation with its rationale. Students should learn the phrase "the control's intent survives; the implementation is negotiable."
NIST CSF 2.0
CSF 2.0's headline change is the addition of GOVERN as a sixth Function, sitting alongside Identify, Protect, Detect, Respond, and Recover. Govern covers organizational context, risk management strategy, roles and responsibilities, policy, oversight, and — newly prominent — cybersecurity supply chain risk management.
For an OT course, CSF's value is communicative rather than technical. A plant manager who will never read IEC 62443-3-3 will happily discuss whether the site is weak on DETECT. Use CSF as the reporting surface and 62443 as the engineering underneath.
5. ISO/IEC 27001 and the Management System
The one that gets audited — and the one most OT courses can safely keep small.
ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System. Its numbered clauses (context, leadership, planning, support, operation, performance evaluation, improvement) are the certifiable part; Annex A lists reference controls, organized in the 2022 edition into four themes — organizational, people, physical, and technological. Detailed implementation guidance lives in the companion standard ISO/IEC 27002.
A health inspector visiting a restaurant does not taste the soup. They check that thermometers are calibrated on a schedule, that the temperature log has entries for every shift, that someone is accountable when a reading is out of range, and that last quarter's corrective actions were closed. ISO/IEC 27001 works the same way: it audits the system that produces security, not the security of any individual control. That is why an organization can hold a certificate and still have a badly configured PLC — the certificate speaks to process discipline within a declared scope.
Worked example — the scope statement trap. Meridian Water District's certificate reads "the ISMS covering corporate IT services delivered from the administration building." That scope excludes every pump station. A student who sees the certificate on the wall and concludes the SCADA network is covered has made exactly the mistake this lesson exists to prevent. Teach students to read the Statement of Applicability and the scope statement before they read anything else.
6. Side by Side
Overlap, difference, and classroom fit in one table.
| Dimension | IEC 62443 | NIST SP 800-82 Rev. 3 | NIST CSF 2.0 | ISO/IEC 27001 |
|---|---|---|---|---|
| Primary scope | IACS across its lifecycle: products, integration, operation | Applying and tailoring security controls to OT environments | Any organization's cybersecurity risk outcomes | Organizational information security management |
| Unit of analysis | Zone, conduit, system under consideration | Control and its OT tailoring | Outcome (Category / Subcategory) | Management system within a declared scope |
| Native to OT? | Yes — designed for it | Yes — an OT-specific guide | No — sector-neutral | No — IT-origin, applicable by scoping |
| Grading scale | Security Levels 0–4 per foundational requirement | None; uses SP 800-53 baselines (low / moderate / high) | Tiers 1–4 describe rigor, not a score | Pass / fail certification audit |
| Certification | Product, process, and personnel certification schemes exist | None — guidance only | None — voluntary framework | Accredited organizational certification |
| Cost to students | Purchase required for most parts; free explainers exist | Free download | Free download | Purchase required |
| Best classroom job | The engineering spine: segmentation, requirements, design labs | Control tailoring and safety-versus-security tradeoff discussions | Executive reporting, program framing, cross-team language | Governance vocabulary and audit literacy |
| Watch out for | Part numbering confuses beginners; paywall limits assignments | Long document; students skim instead of reading the overlay | Feels complete but specifies no OT technique | Certificate scope is routinely misread |
Where they genuinely overlap
All four require you to know what you own, assess risk against consequence, apply proportionate controls, monitor, and improve. Roughly 70–80 percent of the activity is common; what differs is the vocabulary and the depth of engineering specificity. This is why teaching four at once is wasteful — you repeat the same activity four times in four dialects.
Where they genuinely differ
- Only IEC 62443 gives you a repeatable method for partitioning a plant and expressing required adversary resistance per zone.
- Only SP 800-82 systematically addresses what to do when a standard IT control would harm the process.
- Only CSF 2.0 is designed to be readable by someone with no security background, which makes it the right artifact for a board slide.
- Only ISO/IEC 27001 produces an auditable certificate, which is why procurement departments ask for it.
7. Simulation: Zone & Conduit Planner
Assign each asset to a zone, then let the planner derive conduits and flag partitioning findings.
Simulation only — no live equipment, no network traffic, no real plant data.
This planner models the fictional Northline Bottling Plant, Line 2. Assign every asset to a zone, then choose Evaluate my partition. The tool derives the conduits your design implies and checks it against four IEC 62443-3-2 partitioning principles. It is deliberately opinionated: there is more than one defensible answer, and the findings are prompts for discussion, not a grade.
Northline Bottling Plant — Line 2 assets
Assign each asset to a zone, then choose Evaluate my partition. Results appear here.
8. Mapping Lab: Which Framework Owns This Statement?
Six requirements. Match each to the framework that is genuinely its home.
Activity 8.1 — Framework provenance matching
25 minutes · pairsIndividual · 6 min
Answer all six on your own without discussion.Pairs · 10 min
Compare with a partner. Argue any row where you disagree before checking.Share · 9 min
Report the row your pair argued longest about. That row is usually the most teachable.| Requirement statement | Framework of origin |
|---|
9. Choosing One Spine for Your Course
A decision procedure, three defensible outcomes, and the artifact you will build.
A spine is the framework whose vocabulary and structure organize your syllabus. Everything else becomes a supporting reference introduced when it is needed. One spine, cited consistently, beats four surveyed.
You already do this. You adopt one textbook, then supplement with articles, a lab manual, and your own slides. Nobody assigns four textbooks and asks students to reconcile them. Framework selection is textbook adoption with higher stakes and worse marketing.
Decision procedure
- Name the graduate. What job title is the student walking into? A controls technician, an OT analyst in a SOC, or a compliance coordinator? The job decides the dialect.
- Check the constraints. Can students access the documents? IEC 62443 parts are paid; SP 800-82 and CSF are free downloads. This constraint is real and it shapes what you can assign.
- Check the downstream credential. If your program feeds into a certification pathway or an articulation agreement, align to whatever that pathway uses.
- Pick the spine, then demote the rest to references and write that decision into the syllabus so it survives adjunct turnover.
| If your program is… | Use this spine | Because | Bring in the others when… |
|---|---|---|---|
| An industrial maintenance or automation AAS adding a security course | IEC 62443 | Zones, conduits, and Security Levels map directly onto equipment students already touch | SP 800-82 for the patching and availability tradeoff unit; CSF for the final capstone briefing |
| A cybersecurity AAS adding an OT elective | NIST SP 800-82 Rev. 3 | Students already know SP 800-53 language; the overlay teaches OT by contrast, and the document is free | IEC 62443 for the segmentation lab; CSF for governance framing |
| A short workforce or incumbent-worker certificate | NIST CSF 2.0 | Six Functions are learnable in one session and give a shared vocabulary across mixed job roles | IEC 62443 zone concepts inside PROTECT; ISO 27001 named once under GOVERN |
Activity 9.1 — Build your one-page crosswalk (assessment artifact)
30 minutes · individual, then gallery walkYour crosswalk must contain:
- Your spine, named, with a two-sentence rationale that references your program's graduate profile and at least one real constraint (cost, access, articulation, contact hours).
- Your course's five or six major units listed in teaching order, each labelled with the spine's own terminology.
- One supporting reference per unit drawn from the other three frameworks, with a single sentence on what it adds that the spine does not.
- One "commonly confused" note — a place where two frameworks use similar words for different things (for example, "Security Level" in 62443 versus "Tier" in CSF), written in language your students will actually read.
- A safeguards line stating that all coursework is simulation or isolated-bench only.
Success criteria
- A colleague can tell which framework is the spine within five seconds of looking at the page.
- Every supporting reference has a stated reason to exist. No reference is listed "for completeness."
- Terminology is consistent: you do not switch dialects between units.
- The rationale would survive a curriculum committee asking "why not one of the other three?"
Gallery walk. Post your page. Read three others. On a sticky note, write the one question you would ask that author's curriculum committee.
10. Knowledge Check
Five questions. Feedback explains the reasoning, not just the letter.
Further Reading & Downloads
Primary sources cited in this lesson. External links open in a new tab.
Standards and framework pages
The ISA landing page for the full series, including which parts address asset owners, integrators, and product suppliers.
The framework home page, with the Functions, informative references, and quick-start guides.
A deeper treatment of partitioning decisions; useful as an assigned reading for the zone lab.
Downloadable documents
- 📄 Download: NIST SP 800-82 Rev. 3 — Guide to Operational Technology (OT) Security. Assign the OT overlay section, not the whole document.
- 📄 Download: NIST CSF 2.0 — the framework core, including the GOVERN Function.
- 📄 Download: ISAGCA Quick Start Guide — a short orientation to the 62443 series, useful when the full parts are behind a paywall.