← Back

KNOWLEDGE HUB

ISA/IEC 62443: the standard that brings order to industrial cybersecurity

The most complete standards family for securing industrial control systems — where it comes from, how it's structured, and why I use it as my technical backbone.

What it is

ISA/IEC 62443 is a family of international standards for the cybersecurity of Industrial Automation and Control Systems (IACS). It grew out of the ISA99 committee's work and is now jointly maintained by ISA and IEC — hence the double name.

Unlike a generic information-security framework, 62443 was designed from the ground up for the OT world: availability before confidentiality, 15-20 year equipment lifecycles, and devices that can't simply be 'rebooted and patched' like an office server.

Why it matters

It's, to date, the standard most cited by regulators, integrators and manufacturers when they need a common language for OT security. If you work with international vendors, 62443 sooner or later shows up in a contract, a tender document, or an audit.

How it's structured

  • Series 1 — General: terminology and models common to the whole family.
  • Series 2 — Policies and procedures: what the asset owner must do (security program, patch management, incident response).
  • Series 3 — System: how a secure architecture is designed — this is where zones and conduits and Security Levels SL 0 through SL 4 live.
  • Series 4 — Component/product: requirements for whoever manufactures the PLC, the HMI, or the industrial switch.

Best practices

  • Start with segmentation (zones and conduits) before tools — architecture is the foundation, not a product.
  • Define the target Security Level (SL-T) per zone based on actual risk, not the same level across the whole plant.
  • Use 62443-2-1 to build the management program, not just the technical piece — the OT security that survives is the one with process, not just technology.

Common mistakes

  • Treating 62443 as a one-time checklist instead of an ongoing program.
  • Copying IT controls (like aggressive patching policies) without adapting them to OT's availability requirements.
  • Certifying the paperwork without verifying that the actual network architecture matches what's documented.

References

  • ISA/IEC 62443-1-1 — Terminology, concepts and models
  • ISA/IEC 62443-2-1 — Security program requirements
  • ISA/IEC 62443-3-3 — System security requirements and security levels
  • ISA/IEC 62443-4-2 — Technical security requirements for components