Skip to main content

> iec_62443-3-2:2020

IEC 62443-3-2:2020

Security for Industrial Automation and Control Systems — Part 3-2: Security Risk Assessment for System Design

SPEC // INSPECT: IEC 62443-3-2:2020REVIEWED: 2026-09-16
CATEGORYIndustrial & OT Cybersecurity
JURISDICTIONINTERNATIONAL
MANDATORY LEVELTECHNICAL_STANDARD
LIFECYCLE STATUSCURRENT
EXECUTIVE BRIEF SPECIFICATION PDFDISTRIBUTION LOCKED
Fail-Closed Distribution Policy: Download control is visibly disabled until Cloudflare R2 CDN upload and remote SHA-256 verification complete.
[AI // ARCHITECTURAL SUMMARY]

IEC 62443-3-2 provides the canonical engineering methodology for translating industrial operational risk into network architecture. It guides engineers through identifying the System Under Consideration (SuC), performing high-level and detailed risk assessments, partitioning plant assets into Zones and Conduits, and assigning Target Security Levels (SL-T) to each zone.

Scope & Applicability

Applied during greenfield plant engineering, major control system modernization, or plant network architectural redesign.

Non-Coverage Boundaries

Does not dictate the specific brand of firewall or network switch, only the boundary isolation and conduit inspection criteria.

Key Clauses & Control Requirements

sec-z-and-c-partitioning

Zones and Conduits Partitioning

Grouping assets by physical location, functional criticality, and consequence of failure into logically segregated security zones.

sec-sl-t-assignment

Target Security Level (SL-T) Assignment

Assigning SL 1 to SL 4 to each zone based on unmitigated cyber consequence to health, safety, and power generation continuity.

[AUDIT // VERIFIABLE EVIDENCE CHECKLIST]

Required Regulatory & Audit Evidence Artifacts

  • [✓]System Under Consideration (SuC) Definition Document
  • [✓]IACS Detailed Cybersecurity Risk Assessment Report
  • [✓]Formal Zones and Conduits Design Specification with SL-T ratings per zone
[LEADERSHIP TAKEAWAY // CTO & VP OF ENGINEERING DIRECTIVE]
Segmentation without risk assessment is blind firewall configuration. IEC 62443-3-2 ensures that every boundary rule defends a specific operational consequence.
PRIMARY SOURCES & AUTHORITY

Frequently Asked Questions

What is a 'Conduit' in IEC 62443-3-2?

A conduit is a logical or physical communication channel that connects two or more security zones, subject to strict boundary protection and monitoring.