What is BS EN IEC 62443‑3‑2 about?
BS EN IEC 62443‑3‑2 is part three of the multi-series standard that establishes requirements for:
- Defining a system under consideration (SUC) for an industrial automation and control system (IACS)
- Partitioning the SUC into zones and conduits
- Assessing risk for each zone and conduit
- Establishing the target security level (SL-T) for each zone and conduit
- Documenting the security requirements
Who is BS EN IEC 62443‑3‑2 for?
BS EN IEC 62443‑3‑2 on security risk assessment for system design is useful for:
- Organizations using industrial automation and control system
- System integrator
- Manager of industrial automation and control system
- Supplier of industrial automation and control system
- Compliance authorities
Why should you use BS EN IEC 62443‑3‑2?
Industrial automation and control system (IACS) presents a different risk to the organization depending upon the risks it is exposed to, the likelihood of those threats arising, the inherent vulnerabilities in the system and the consequences if the system were to be compromised. Furthermore, every organization that owns and operates an IACS has a different tolerance for risk.
BS EN IEC 62443‑3‑2 strives to define a set of engineering measures that will guide an organization through the process of security risk assessment for system design of IACS and identifying and applying security countermeasures to reduce that risk to tolerable levels.
A key concept in BS EN IEC 62443‑3‑2 is the application of IACS security zones and conduits. BS EN IEC 62443‑3‑2 has been developed in cooperation with the ISA99 liaison. ISA99 is the
committee on Industrial Automation and Control Systems Security of the International Society of Automation (ISA).
BS EN IEC 62443‑3‑2 provides a basis for specifying security countermeasures by aligning the target security levels (SL-Ts) identified in this document with the required capability security levels (SL-Cs) specified in IEC 62443-3-3.