← Back to Library
IEC 62443-3-2

IEC 62443-3-2 (v1.0)

Full Name:
International Electrotechnical Commission (IEC) 62443 Part 3-2 - Security risk assessment and system design
Acronym:
IEC 62443 Part 3-2
Type:
International Standard
Organization:
International Electrotechnical Commission
Version:
1
Year Published:
2020
Popularity:
Moderate

Overview of IEC 62443-3-2

IEC 62443-3-2:2020, published by the International Electrotechnical Commission, establishes a comprehensive methodology for conducting security risk assessments during the design phase of Industrial Automation and Control Systems (IACS). This standard provides structured processes for identifying security risks, determining appropriate security levels, and establishing security requirements that guide system design and implementation. Unlike general IT risk assessment methodologies, IEC 62443-3-2 addresses the unique characteristics of IACS environments, including the integration of IT and operational technology, legacy system constraints, safety implications, and operational availability requirements.

The standard emerged in 2020 as a critical component of the IEC 62443 series, filling an important gap by providing systematic approaches to security risk assessment specifically tailored for industrial control systems. IEC 62443-3-2 recognizes that effective IACS security begins during system design, where security requirements can be integrated into system architecture rather than added as afterthoughts. The standard provides methodologies for partitioning IACS into security zones and conduits, assessing risks for each partition, determining target security levels based on risk, and documenting security requirements that inform system design decisions.

IEC 62443-3-2 serves as a foundational standard that supports implementation of other IEC 62443 parts, particularly IEC 62443-3-3 which specifies system security requirements and security levels. Organizations conducting security risk assessments using IEC 62443-3-2 methodologies establish the basis for determining which security requirements from IEC 62443-3-3 must be implemented to achieve desired security levels. The standard applies to new IACS designs, major system modifications, and security assessments of existing systems, providing flexibility for various implementation scenarios while maintaining consistent risk assessment approaches.

Framework Applicability and Adoption

IEC 62443-3-2 applies to any organization designing, implementing, or assessing Industrial Automation and Control Systems, regardless of industry sector or system complexity. The standard is particularly relevant for system integrators designing new IACS installations, asset owners planning major system upgrades, engineering firms providing design services, and organizations conducting security assessments of existing systems. Organizations operating in sectors including energy, water and wastewater, manufacturing, chemical processing, oil and gas, and other critical infrastructure domains find IEC 62443-3-2 essential for establishing security requirements during system design.

Many organizations adopt IEC 62443-3-2 methodologies as part of comprehensive IACS security programs, recognizing that security risk assessment during design phase enables cost-effective security implementation and avoids costly retrofitting of security controls. System integrators implementing IEC 62443-3-2 can demonstrate to customers that security has been systematically addressed in system design, while asset owners using the standard can ensure that security requirements are established before system procurement and implementation. The standard's adoption has accelerated as organizations recognize the value of security-by-design approaches and seek structured methodologies for IACS security risk assessment.

IEC 62443-3-2 complements other IEC 62443 parts, with organizations typically implementing the standard as part of comprehensive IACS security programs that also include IEC 62443-2-1 for CSMS, IEC 62443-3-3 for system security requirements, and other relevant parts. The standard provides the risk assessment foundation that informs security requirement selection and security level determination, making it essential for organizations seeking comprehensive IACS security management.

Key Framework Components and Control Domains

IEC 62443-3-2 organizes security risk assessment processes into several key phases that guide organizations through systematic risk assessment and security requirement establishment. The standard provides structured methodologies for each phase, ensuring that risk assessments are comprehensive, repeatable, and produce actionable security requirements.

System Under Consideration (SUC) Definition

IEC 62443-3-2 requires organizations to clearly define the System Under Consideration (SUC), establishing the boundaries and scope of the IACS being assessed. SUC definition must identify all components, networks, and functions included in the system, as well as interfaces to external systems and dependencies on supporting infrastructure. The standard emphasizes that SUC definition must be comprehensive and accurate, as incomplete or inaccurate definitions lead to incomplete risk assessments and inadequate security requirements.

SUC definition processes must document system functions, operational requirements, safety considerations, and business objectives, ensuring that security risk assessments account for all relevant factors. Organizations must identify all IACS components including programmable logic controllers (PLCs), distributed control systems (DCS), human-machine interfaces (HMIs), engineering workstations, network infrastructure, and any other devices or systems that support IACS operations. SUC definition must also identify external interfaces including connections to business IT networks, remote access capabilities, vendor support connections, and any other external connectivity that could introduce security risks.

Zone and Conduit Partitioning

IEC 62443-3-2 requires organizations to partition the SUC into security zones and conduits, creating logical groupings of IACS components based on security requirements, criticality, and risk exposure. Security zones represent groups of IACS components that share common security requirements and can be protected by common security controls. Zones enable organizations to implement security controls appropriate for each zone's risk level, avoiding over-protection of low-risk areas and under-protection of high-risk areas.

Conduits represent communication paths between security zones, including network connections, serial links, and any other communication mechanisms that enable data flow between zones. Conduit partitioning enables organizations to implement security controls that protect communications between zones, preventing unauthorized access and ensuring that security zone boundaries are maintained. The standard requires organizations to document zone and conduit definitions clearly, including rationale for partitioning decisions, zone characteristics, and conduit security requirements.

Zone partitioning must consider factors including functional relationships between components, criticality to operations and safety, exposure to threats, and operational requirements. Organizations should create zones that group components with similar security needs, enabling efficient security control implementation while maintaining operational functionality. Conduit partitioning must identify all communication paths between zones, assess security risks associated with each conduit, and establish security requirements for conduit protection.

Threat Identification and Analysis

IEC 62443-3-2 requires organizations to identify and analyze threats that could affect each security zone and conduit, recognizing that IACS face unique threat vectors including targeted attacks on critical infrastructure, accidental misconfigurations, supply chain compromises, and insider threats. Threat identification must consider IACS-specific attack scenarios including manipulation of process control parameters, disruption of production operations, attacks on safety systems, and theft of proprietary process information.

The standard requires organizations to analyze threats systematically, considering threat sources including external attackers, insiders, vendors, and natural disasters. Threat analysis must assess threat capabilities, motivations, and likelihood, enabling organizations to prioritize threats based on their potential impact and probability. Organizations must consider both intentional threats including cyber attacks and unintentional threats including human error, equipment failures, and natural disasters that could affect IACS security.

Threat identification processes must account for evolving threat landscapes, including emerging attack techniques, new vulnerabilities, and changing threat actor capabilities. Organizations should leverage threat intelligence sources specific to IACS, participate in information sharing organizations, and maintain awareness of threat trends affecting industrial control systems. Threat analysis must be documented comprehensively, enabling organizations to trace security requirements back to specific threats and justify security control selections.

Vulnerability Assessment

IEC 62443-3-2 requires organizations to assess vulnerabilities in IACS components, networks, and processes that could be exploited by identified threats. Vulnerability assessment must consider technical vulnerabilities including unpatched software, default credentials, insecure configurations, and inadequate access controls, as well as procedural vulnerabilities including insufficient change management, inadequate training, and weak security policies. Organizations must assess vulnerabilities systematically, identifying weaknesses that could enable threat exploitation.

Vulnerability assessment processes must account for IACS-specific concerns including legacy systems with limited security capabilities, proprietary protocols that may have unknown vulnerabilities, and operational constraints that limit security control implementation. Organizations should conduct vulnerability assessments using appropriate methodologies for IACS environments, recognizing that traditional IT vulnerability scanning tools may not be suitable for industrial control systems. Vulnerability assessments must be documented comprehensively, enabling organizations to understand security weaknesses and prioritize remediation activities.

Risk Evaluation and Security Level Determination

IEC 62443-3-2 requires organizations to evaluate risks by combining threat likelihood, vulnerability existence, and potential consequences, enabling systematic risk prioritization and security level determination. Risk evaluation must consider consequences including safety implications, environmental damage, production disruptions, business continuity effects, and data confidentiality or integrity impacts. Organizations must assess risks comprehensively, ensuring that all significant risks are identified and evaluated.

The standard requires organizations to determine target security levels (SL-T) for each security zone and conduit based on risk evaluation results. Security levels range from SL 1 (protection against casual or coincidental violation) to SL 4 (protection against intentional violation using sophisticated means with extended resources). Security level determination must be risk-based, with higher-risk zones and conduits requiring higher security levels. Organizations must document security level determinations clearly, including rationale for selections and risk factors that informed decisions.

Risk evaluation processes must account for IACS-specific risk factors including safety implications of security incidents, operational availability requirements, and integration with other systems. Organizations should involve stakeholders including operations personnel, safety engineers, and business leadership in risk evaluation activities, ensuring that risk assessments account for all relevant perspectives. Risk evaluation results must inform security requirement selection, enabling organizations to implement security controls appropriate for identified risks.

Security Requirement Documentation

IEC 62443-3-2 requires organizations to document security requirements comprehensively, ensuring that security requirements are clearly specified and can guide system design and implementation. Security requirement documentation must specify security levels for each zone and conduit, identify security requirements from IEC 62443-3-3 that must be implemented, and document any additional security requirements specific to the SUC. Documentation must be clear, complete, and actionable, enabling system designers and implementers to understand security requirements and implement appropriate security controls.

The standard requires organizations to maintain security requirement documentation throughout system lifecycle, updating requirements as threats evolve, vulnerabilities are discovered, or system changes occur. Security requirement documentation must be accessible to all stakeholders involved in system design, implementation, and operation, ensuring that security requirements are understood and implemented consistently. Organizations must establish processes for reviewing and updating security requirements, ensuring that requirements remain current and effective.

Implementation Strategies and Best Practices

Successfully implementing IEC 62443-3-2 requires organizations to establish structured risk assessment processes, engage appropriate stakeholders, and integrate security risk assessment into system design workflows. Organizations should begin by establishing risk assessment methodologies based on IEC 62443-3-2 requirements, ensuring that assessment processes are systematic, repeatable, and produce actionable results.

Establish Cross-Functional Risk Assessment Teams: Effective security risk assessment requires input from diverse stakeholders including security professionals, operations personnel, safety engineers, system designers, and business leadership. Organizations should establish risk assessment teams that include representatives from all relevant disciplines, ensuring that risk assessments account for security, operational, safety, and business perspectives. Risk assessment teams must have clear roles and responsibilities, adequate expertise, and sufficient authority to make risk assessment decisions.

Integrate Risk Assessment into System Design Processes: Security risk assessment should be integrated into standard system design workflows, not conducted as separate activities. Organizations should establish processes that require security risk assessment at appropriate design phases, ensuring that security requirements are identified early and can be incorporated into system architecture. Integration enables security-by-design approaches that avoid costly retrofitting of security controls and ensure that security is considered throughout system development.

Develop Comprehensive SUC Definitions: Accurate and complete SUC definitions are essential for effective risk assessment. Organizations should invest time in developing comprehensive SUC definitions, identifying all components, networks, functions, and interfaces. SUC definitions should be documented clearly, reviewed by stakeholders, and updated as system designs evolve. Incomplete SUC definitions lead to incomplete risk assessments and inadequate security requirements.

Implement Systematic Zone and Conduit Partitioning: Zone and conduit partitioning should be systematic and well-documented, enabling organizations to implement security controls efficiently. Organizations should partition systems based on security requirements, criticality, and risk exposure, creating zones that group components with similar security needs. Partitioning decisions should be documented clearly, including rationale for partitioning choices and security requirements for each zone and conduit.

Conduct Comprehensive Threat and Vulnerability Analysis: Threat and vulnerability analysis must be comprehensive, accounting for all significant threats and vulnerabilities that could affect IACS. Organizations should leverage threat intelligence sources, conduct systematic vulnerability assessments, and involve stakeholders with diverse expertise in threat and vulnerability analysis. Analysis results must be documented comprehensively, enabling organizations to trace security requirements back to specific threats and vulnerabilities.

Establish Risk-Based Security Level Determination: Security level determination must be risk-based, with security levels selected based on risk evaluation results. Organizations should establish clear criteria for security level selection, ensuring that security levels are appropriate for identified risks. Security level determinations should be documented clearly, including rationale for selections and risk factors that informed decisions.

Maintain Comprehensive Security Requirement Documentation: Security requirement documentation must be comprehensive, clear, and actionable. Organizations should establish documentation standards that ensure security requirements are specified clearly and can guide system design and implementation. Documentation should be maintained throughout system lifecycle, updated as threats evolve or system changes occur, and made accessible to all relevant stakeholders.

Relationship to Other Frameworks and Standards

IEC 62443-3-2 exists within the broader IEC 62443 series, with important relationships to other parts that enable comprehensive IACS security management. Understanding these relationships helps organizations implement IEC 62443 standards effectively and avoid duplicative efforts.

IEC 62443-3-2 provides the risk assessment foundation that supports implementation of IEC 62443-3-3, which specifies system security requirements and security levels. Organizations conducting security risk assessments using IEC 62443-3-2 methodologies determine target security levels that inform selection of security requirements from IEC 62443-3-3. The standards work together, with IEC 62443-3-2 establishing what security levels are needed and IEC 62443-3-3 specifying what security requirements achieve those levels.

The standard supports implementation of IEC 62443-2-1, which addresses CSMS requirements for asset owners. Security risk assessment represents a critical component of CSMS, with IEC 62443-2-1 requiring organizations to conduct risk assessments as part of security program management. Organizations implementing IEC 62443-2-1 can use IEC 62443-3-2 methodologies to conduct systematic security risk assessments that support CSMS requirements.

IEC 62443-3-2 relates to IEC 62443-2-4, which addresses security requirements for service providers. System integrators and other service providers implementing IEC 62443-2-4 should use IEC 62443-3-2 methodologies when conducting security risk assessments as part of system design and implementation services. The standards work together to ensure that service providers conduct systematic risk assessments and establish appropriate security requirements.

The standard aligns with ISO/IEC 27001 and ISO/IEC 27005, which address information security risk management. While ISO standards provide general risk management guidance, IEC 62443-3-2 provides IACS-specific risk assessment methodologies that address unique industrial control system concerns. Organizations implementing ISO 27001 can use IEC 62443-3-2 to conduct IACS-specific risk assessments that support broader information security management systems.

Common Challenges and Solutions

Organizations implementing IEC 62443-3-2 frequently encounter similar challenges related to the complexity of IACS risk assessment and the need to balance security with operational requirements. Understanding these common challenges helps organizations plan proactively and implement risk assessment processes effectively.

Defining Comprehensive System Boundaries: Organizations often struggle to define SUC boundaries comprehensively, leading to incomplete risk assessments that miss important components or interfaces. Incomplete SUC definitions result in incomplete risk assessments and inadequate security requirements. Solutions include involving diverse stakeholders in SUC definition, conducting systematic component inventories, identifying all external interfaces, and documenting SUC definitions clearly. Organizations should review SUC definitions regularly and update them as system designs evolve.

Partitioning Systems into Appropriate Zones and Conduits: Zone and conduit partitioning can be challenging, particularly for complex IACS with many components and communication paths. Organizations may struggle to determine appropriate partitioning strategies, balance security requirements with operational needs, and document partitioning decisions clearly. Solutions include establishing clear partitioning criteria based on security requirements and criticality, involving operations personnel in partitioning decisions, documenting partitioning rationale comprehensively, and reviewing partitioning decisions as system designs evolve.

Identifying and Analyzing IACS-Specific Threats: Organizations may lack expertise in identifying IACS-specific threats, particularly threats targeting industrial control systems rather than general IT systems. Traditional IT security professionals may not understand IACS threat vectors, while operations personnel may not understand cybersecurity threats. Solutions include leveraging IACS-specific threat intelligence sources, involving both security and operations personnel in threat identification, participating in IACS security information sharing organizations, and maintaining awareness of threat trends affecting industrial control systems.

Assessing Vulnerabilities in Legacy and Proprietary Systems: IACS environments often include legacy systems and proprietary protocols that present challenges for vulnerability assessment. Traditional vulnerability scanning tools may not work with industrial control systems, and organizations may lack visibility into proprietary system vulnerabilities. Solutions include using IACS-specific vulnerability assessment tools, conducting manual security reviews, working with vendors to understand system security characteristics, and implementing compensating controls for systems with unknown vulnerabilities.

Determining Appropriate Security Levels: Security level determination can be challenging, particularly when balancing security requirements with operational needs and cost constraints. Organizations may struggle to determine appropriate security levels, justify security level selections, and communicate security level requirements to stakeholders. Solutions include establishing clear security level selection criteria, involving diverse stakeholders in security level determination, documenting security level rationale comprehensively, and reviewing security level determinations as threats evolve or system changes occur.

Integrating Risk Assessment into Design Processes: Organizations may struggle to integrate security risk assessment into standard system design workflows, treating risk assessment as separate activities rather than integrated design processes. This can result in security requirements being identified too late in design processes, requiring costly retrofitting of security controls. Solutions include establishing design processes that require risk assessment at appropriate phases, training design personnel on risk assessment methodologies, and ensuring that security requirements inform design decisions throughout system development.

Frequently Asked Questions

What is the difference between IEC 62443-3-2 and general IT risk assessment methodologies?

IEC 62443-3-2 provides risk assessment methodologies specifically designed for Industrial Automation and Control Systems, addressing unique IACS characteristics including IT/OT integration, legacy system constraints, safety implications, and operational availability requirements. Unlike general IT risk assessment methodologies, IEC 62443-3-2 addresses IACS-specific threat vectors, considers safety consequences of security incidents, accounts for operational constraints, and provides methodologies for zone and conduit partitioning that are specific to industrial control systems. The standard recognizes that IACS risk assessment must balance security with operational requirements, avoiding security controls that could compromise safety or create unacceptable production disruptions.

How do zones and conduits relate to security risk assessment?

Zones and conduits enable organizations to partition IACS into logical groupings based on security requirements, criticality, and risk exposure, enabling risk assessment and security control implementation at appropriate granularity. Zones group IACS components that share common security requirements, enabling organizations to assess risks and implement security controls for each zone independently. Conduits represent communication paths between zones, enabling organizations to assess risks associated with inter-zone communications and implement security controls that protect communications. Zone and conduit partitioning enables organizations to implement security controls appropriate for each partition's risk level, avoiding over-protection of low-risk areas and under-protection of high-risk areas.

How are target security levels determined in IEC 62443-3-2?

Target security levels are determined based on risk evaluation results, with security levels selected to address identified risks appropriately. Organizations evaluate risks by combining threat likelihood, vulnerability existence, and potential consequences, then determine security levels that provide appropriate protection for identified risks. Security levels range from SL 1 (protection against casual violations) to SL 4 (protection against sophisticated attacks), with higher-risk zones and conduits requiring higher security levels. Security level determination must be risk-based, documented clearly, and reviewed as threats evolve or system changes occur.

How does IEC 62443-3-2 relate to IEC 62443-3-3?

IEC 62443-3-2 provides risk assessment methodologies that determine what security levels are needed, while IEC 62443-3-3 specifies what security requirements achieve those security levels. Organizations conducting security risk assessments using IEC 62443-3-2 determine target security levels for each zone and conduit, then use IEC 62443-3-3 to identify specific security requirements that must be implemented to achieve those security levels. The standards work together, with IEC 62443-3-2 establishing security requirements based on risk and IEC 62443-3-3 providing detailed security requirement specifications.

When should IEC 62443-3-2 risk assessments be conducted?

IEC 62443-3-2 risk assessments should be conducted during system design phases, enabling security requirements to be integrated into system architecture rather than added as afterthoughts. Risk assessments should be conducted for new IACS designs, major system modifications, and security assessments of existing systems. Organizations should conduct risk assessments at appropriate design phases, ensuring that security requirements are identified early and can inform design decisions. Risk assessments should be updated as threats evolve, vulnerabilities are discovered, or system changes occur, ensuring that security requirements remain current and effective.

Conclusion

IEC 62443-3-2:2020 provides essential methodologies for conducting security risk assessments during IACS system design, enabling organizations to establish security requirements based on systematic risk evaluation. As a foundational standard in the IEC 62443 series, IEC 62443-3-2 supports implementation of other IEC 62443 parts by providing risk assessment processes that determine security levels and inform security requirement selection.

Successful IEC 62443-3-2 implementation requires establishing structured risk assessment processes, engaging diverse stakeholders, and integrating security risk assessment into system design workflows. Organizations should approach risk assessment as an integral part of system design rather than separate activities, enabling security-by-design approaches that avoid costly retrofitting and ensure that security is considered throughout system development.

By following IEC 62443-3-2 methodologies, maintaining comprehensive documentation, and continuously updating risk assessments as threats evolve and systems change, organizations can establish security requirements that effectively address IACS security risks while maintaining operational functionality. The investment in systematic security risk assessment pays dividends through improved security posture, reduced security incidents, enhanced customer confidence, and strengthened ability to protect critical industrial control systems in an increasingly threatened environment.