IEC 62443-2-1:2010
Industrial communication networks - Network and system security - Part 2-1: Establishing an industrial automation and control system security program
Industrial communication networks - Network and system security - Part 2-1: Establishing an industrial automation and control system security program
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 159
- Дата публикации:
- 10 ноября 2010 г.
- Издание:
- IEC IS 62443 edition 1 version 1
- ICS:
- 25.040.40
IEC 62443-2-1:2010 defines the elements necessary to establish a cyber security management system (CSMS) for industrial automation and control systems (IACS) and provides guidance on how to develop those elements. This standard uses the broad definition and scope of what constitutes an IACS described in IEC/TS 62443-1-1. The elements of a CSMS described in this standard are mostly policy, procedure, practice and personnel related, describing what shall or should be included in the final CSMS for the organization. This bilingual version (2012-04) corresponds to the monolingual English version, published in 2010-11.
Abstract
Overview
IEC 62443-2-1:2010 specifies the elements required to establish a Cyber Security Management System (CSMS) for Industrial Automation and Control Systems (IACS). Part of the IEC 62443 series on industrial communication networks and network/system security, this standard is primarily focused on policy, procedures, practices and personnel elements of IACS security and provides guidance on developing and maintaining those elements. It aligns with the broad IACS scope described in IEC/TS 62443-1-1 and includes informative annexes with guidance, a CSMS development process, and a mapping to ISO/IEC 27001.
Key topics and requirements
IEC 62443-2-1 structures CSMS requirements across a lifecycle and includes these core categories:
- Risk analysis
- Business rationale, asset identification, risk identification, classification and assessment.
- Addressing risk through the CSMS
- Security policy, organization and awareness (scope, responsibilities, staff training, business continuity).
- Selected security countermeasures (examples include network segmentation, access control - account administration, authentication, authorization - physical/environmental security).
- Implementation (risk management, system development & maintenance, document management, incident planning & response).
- Monitoring and continuous improvement
- Conformance, review, and ongoing CSMS maintenance.
The standard contains detailed requirement tables (e.g., Tables 3–19) and lifecycle models, plus illustrative figures and examples to help map security levels, zone architectures and implementation steps.
Practical applications
IEC 62443-2-1 is used to:
- Establish or mature an OT/ICS-focused CSMS that addresses unique operational availability and safety constraints.
- Guide risk assessments and specify organizational controls, policies, and incident response tailored to IACS.
- Provide a structured approach to integrating technical countermeasures (network segmentation, access controls) with organizational processes.
- Support compliance and conformance efforts by mapping CSMS elements to ISO/IEC 27001 controls (see Annex C).
Who should use this standard
- IACS owners/operators (utilities, manufacturing, energy, water).
- OT/SCADA/ICS engineers and control system integrators.
- Cybersecurity managers, compliance officers and auditors working in operational technology (OT).
- Security consultants and vendors implementing CSMS, policies or defense-in-depth architectures.
Related standards
- IEC/TS 62443-1-1 (IACS terminology & concepts)
- Other parts of the IEC 62443 series (technical and product-level requirements)
- ISO/IEC 27001 (information security management) - Annex C provides a mapping between IEC 62443-2-1 and ISO/IEC 27001.
Keywords: IEC 62443-2-1, CSMS, IACS security, industrial control systems security, OT security, SCADA security, network and system security.
Технические детали
- Технический комитет
- TC 65 - Industrial-process measurement, control and automation
- SKU
- IEC 62443-2-1:2010
Похожие стандарты
Упомянутые в описании и другие стандарты IEC
IEC 62443-3-3:2013
ДействующийIndustrial communication networks - Network and system security - Part 3-3: System security requirements and…
Overview IEC 62443-3-3:2013 - Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels - defines detailed technical requirements fo…
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
IEC 62590-2-2:2026
ДействующийRailway applications - Electronic power converters for fixed installations - Part 2-2: DC Traction applicatio…
Overview IEC 62590-2-2:2026 is an international standard developed by the International Electrotechnical Commission (IEC) focusing on railway applications, specifically the electronic power converter…
IEC 61753-042-02:2026
ДействующийFibre optic interconnecting devices and passive components - Performance standard - Part 042-02: Plug-pigtail…
Overview IEC 61753-042-02:2026 establishes the minimum performance, test, and measurement requirements for plug-pigtail and plug-receptacle style OTDR (Optical Time-Domain Reflectometer) reflecting d…
IEC 61837-2:2018
ДействующийSurface mounted piezoelectric devices for frequency control and selection - Standard outlines and terminal le…
Overview IEC 61837-2:2018 - Surface mounted piezoelectric devices for frequency control and selection - Standard outlines and terminal lead connections - Part 2: Ceramic enclosures (Edition 3.0, 2018…
IEC 61851-23-1:2026
ДействующийElectric vehicle conductive charging system - Part 23-1: DC electric vehicle supply equipment - Automated con…
Overview IEC 61851-23-1:2026 is an international standard published by the International Electrotechnical Commission (IEC) that specifies requirements for DC electric vehicle supply equipment (EVSE)…
IEC 63506:2026
ДействующийCalibration of the prompt fission neutron logging tools
Overview IEC 63506:2026 - Calibration of the Prompt Fission Neutron Logging Tools is the international standard that specifies the calibration methods for prompt fission neutron (PFN) logging tools,…
IEC 63589-1:2026
ДействующийLinear accelerator - Electron linear accelerator for radiation processing - Part 1: General requirements and…
Overview IEC 63589-1:2026 specifies the general requirements and test methods for electron linear accelerator devices used in radiation processing. Developed by the International Electrotechnical Com…