What is BS EN IEC 62443-3-3 - Network and system security about?
BS EN IEC 62443-3-3 is the third part of the IEC 62443 series which provides detailed technical control system requirements (SRs) associated with the seven foundational requirements (FRs) described in IEC 62443‑1‑1 including defining the requirements for control system capability security levels, SL-C (control system).
These requirements would be used by various members of the industrial automation and control system (IACS) community along with the defined zones and conduits for the system under consideration (SuC) while developing the appropriate control system target SL, SL-T(control system), for a specific asset.
Who is BS EN IEC 62443-3-3- Network and system security for?
BS EN IEC 62443-3-3 on system security requirements and security levels of Industrial communication networks is useful for:
- Asset owners
- System integrators
- Product suppliers
- Service providers
- Government agencies and regulators
- Legal authorities
Why should you use BS EN IEC 62443-3-3- Network and system security?
The devices with open networking technologies and increased connectivity provide an increased opportunity for cyberattacks against control system hardware and software. That weakness may lead to health, safety, and environmental (HSE), financial, and/or reputational consequences in deployed control systems. BS EN IEC 62443-3-3 provides system integrators and service providers with a flexible framework that facilitates addressing current and future vulnerabilities in IACS and applying necessary mitigations in a systematic, defensible manner. Many business IT applications and security solutions can be applied to IACS but they need to be applied in an appropriate way to eliminate inadvertent consequences. BS EN IEC 62443-3-3 provides the approach based on a combination of functional requirements and risk assessment, including an awareness of operational issues as well.
BS EN IEC 62443-3-3 can be used by system integrators, product suppliers, and service providers to evaluate whether their products and services can provide the functional security capability to meet the asset owner’s target security level (SL-T) requirements.
BS EN IEC 62443-3-3 defines a common, minimum set of requirements to reach progressively more stringent security levels which will help service providers to improve their security