> iec_62443-3-2:2020
IEC 62443-3-2:2020
Security for Industrial Automation and Control Systems — Part 3-2: Security Risk Assessment for System Design
IEC 62443-3-2 provides the canonical engineering methodology for translating industrial operational risk into network architecture. It guides engineers through identifying the System Under Consideration (SuC), performing high-level and detailed risk assessments, partitioning plant assets into Zones and Conduits, and assigning Target Security Levels (SL-T) to each zone.
Scope & Applicability
Applied during greenfield plant engineering, major control system modernization, or plant network architectural redesign.
Non-Coverage Boundaries
Does not dictate the specific brand of firewall or network switch, only the boundary isolation and conduit inspection criteria.
Key Clauses & Control Requirements
Zones and Conduits Partitioning
Grouping assets by physical location, functional criticality, and consequence of failure into logically segregated security zones.
Target Security Level (SL-T) Assignment
Assigning SL 1 to SL 4 to each zone based on unmitigated cyber consequence to health, safety, and power generation continuity.
Required Regulatory & Audit Evidence Artifacts
- [✓]System Under Consideration (SuC) Definition Document
- [✓]IACS Detailed Cybersecurity Risk Assessment Report
- [✓]Formal Zones and Conduits Design Specification with SL-T ratings per zone
“Segmentation without risk assessment is blind firewall configuration. IEC 62443-3-2 ensures that every boundary rule defends a specific operational consequence.”
Cross-Surface Ecosystem Relationships
- IEC 62443-3-2:2020 Security risk assessment for system design ↗(International Electrotechnical Commission)
Frequently Asked Questions
What is a 'Conduit' in IEC 62443-3-2?
A conduit is a logical or physical communication channel that connects two or more security zones, subject to strict boundary protection and monitoring.
