logo

ISA/IEC 62443


Summary

The ISA/IEC 62443 standard defines the necessary elements to establish a cyber security management system (CSMS) for industrial automation and control systems (IACS) and provides guidance on how to develop those elements. The version used in this section is IEC 62443-3-3 edition 1.0 2013-08.


Definitions

DefinitionRequirements
IEC62443-IAC-1_1. Human user identification and authentication
IEC62443-IAC-1_2. Software process and device identification and authentication
IEC62443-IAC-1_3. Account management
IEC62443-IAC-1_5. Authenticator management
IEC62443-IAC-1_6. Wireless access management
IEC62443-IAC-1_7. Strength of password-based authentication
IEC62443-IAC-1_8. Public key infrastructure (PKI) certificates
IEC62443-IAC-1_9. Strength of public key authentication
IEC62443-IAC-1_11. Unsuccessful login attempts
IEC62443-IAC-1_12. System use notification
IEC62443-IAC-1_13. Access via untrusted networks
IEC62443-UC-2_1. Authorization enforcement
IEC62443-UC-2_2. Wireless use control
IEC62443-UC-2_3. Use control for portable and mobile devices
IEC62443-UC-2_4. Mobile code
IEC62443-UC-2_6. Remote session termination
IEC62443-UC-2_7. Concurrent session control
IEC62443-UC-2_8. Auditable events
IEC62443-UC-2_9. Audit storage capacity
IEC62443-UC-2_11. Timestamps
IEC62443-SI-3_1. Communication integrity
IEC62443-SI-3_2. Malicious code protection
IEC62443-SI-3_5. Input validation
IEC62443-SI-3_7. Error handling
IEC62443-SI-3_8. Session integrity
IEC62443-SI-3_9. Protection of audit information
IEC62443-DC-4_1. Information confidentiality
IEC62443-DC-4_3. Use of cryptography
IEC62443-RDF-5_1. Network segmentation
IEC62443-RDF-5_2. Zone boundary protection
IEC62443-RDF-5_3. User content filtering
IEC62443-TRE-6_1. Audit log accessibility
IEC62443-RA-7_1. Denial of service protection
IEC62443-RA-7_6. Network and security configuration settings
IEC62443-RA-7_7. Least functionality
IEC62443-CR-1_1-RE_1. Unique identification and authentication
IEC62443-CR-1_1-RE_2. Multifactor authentication for all interfaces
IEC62443-CR-1_7. Strength of password-based authentication
IEC62443-CR-1_7-RE_2. Password lifetime restrictions for all users
IEC62443-CR-2_1-RE_3. Permission mapping to roles
IEC62443-CR-3_1-RE_1. Communication authentication

Last updated

2023/09/18