IEC 62443-2-1:2024
Security for industrial automation and control systems - Part 2-1: Security program requirements for IACS asset owners
Security for industrial automation and control systems - Part 2-1: Security program requirements for IACS asset owners
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 189
- Дата публикации:
- 7 августа 2024 г.
- Издание:
- IEC IS 62443 edition 2 version 1
- ICS:
- 25.040.40
IEC 62443-2-1:2024 specifies asset owner security program (SP) policy and procedure requirements for an industrial automation and control system (IACS) in operation. This document uses the broad definition and scope of what constitutes an IACS as described in IEC TS 62443‑1‑1. In the context of this document, asset owner also includes the operator of the IACS. This document recognizes that the lifespan of an IACS can exceed twenty years, and that many legacy systems contain hardware and software that are no longer supported. Therefore, the SP for most legacy systems addresses only a subset of the requirements defined in this document. For example, if IACS or component software is no longer supported, security patching requirements cannot be met. Similarly, backup software for many older systems is not available for all components of the IACS. This document does not specify that an IACS has these technical requirements. This document states that the asset owner needs to have policies and procedures around these types of requirements. In the case where an asset owner has legacy systems that do not have the native technical capabilities, compensating security measures can be part of the policies and procedures specified in this document. This edition includes the following significant technical changes with respect to the previous edition: a) revised requirement structure into SP elements (SPEs), b) revised requirements to eliminate duplication of an information security management system (ISMS), and c) defined a maturity model for evaluating requirements.
Abstract
Overview
IEC 62443-2-1:2024 is a key international standard published by the International Electrotechnical Commission (IEC) that defines security program requirements for Industrial Automation and Control System (IACS) asset owners. This updated edition focuses on establishing robust security policies and procedures for asset owners and operators managing industrial control systems that often have lifespans exceeding twenty years. Recognizing the challenges posed by legacy systems and unsupported hardware/software, the standard emphasizes adaptable security programs with compensating controls where direct technical solutions are unavailable.
This edition introduces a revised structure based on Security Program Elements (SPEs), removes duplicative requirements with information security management systems (ISMS), and includes a maturity model to assess compliance levels. IEC 62443-2-1:2024 supports industrial sectors in safeguarding their automation infrastructure against evolving cyber threats through comprehensive, lifecycle-oriented security governance.
Key Topics
-
Asset Owner Security Program (SP) Requirements: Defines organizational policies and procedures for managing IACS security risks over operational lifecycles-including legacy and outdated technologies.
-
Security Program Elements (SPEs): Structured categorization of requirements into:
- Organizational security measures
- Configuration management
- Network and communications security
- Component security
- Protection of data
- User access control
-
Legacy System Considerations: Addresses challenges like unsupported software, unavailable patches, and backup limitations by recommending compensating controls within security policies.
-
Maturity Model for Evaluation: Provides a framework to assess the effectiveness and maturity of an asset owner’s security programs, facilitating continuous improvement.
-
Conformance and Assessment: Guidelines for assessing conformity and collecting evidence to demonstrate compliance with the standard’s security program requirements.
-
Risk Mitigation and Anomaly Detection: Emphasizes ongoing risk assessments, security reviews, and processes to detect and respond to security incidents within the IACS environment.
Applications
IEC 62443-2-1:2024 applies primarily to:
-
Industrial Automation Asset Owners and Operators: Entities responsible for managing and securing automation and control systems in industries such as manufacturing, energy, water treatment, oil and gas, and critical infrastructure.
-
Security Program Development: Creating or refining organizational security programs tailored to the unique risks and operational realities of industrial control systems.
-
Legacy System Management: Guiding asset owners in implementing compensating security measures when direct technical solutions like patching are unavailable.
-
Cybersecurity Governance: Establishing a comprehensive security management approach that integrates with broader organizational frameworks including ISMS.
-
Supply Chain and Third-Party Security: Mitigating risks associated with service providers and vendors involved with IACS components and maintenance.
-
Compliance and Audit Preparation: Supporting compliance with regulatory requirements related to industrial cybersecurity by defining measurable security program criteria.
Related Standards
-
IEC TS 62443-1-1: Provides foundational concepts and terminology used within the IEC 62443 series, including defining what constitutes an Industrial Automation and Control System (IACS).
-
IEC 62443 Series: A comprehensive set of standards covering multiple IACS security aspects, such as:
- IEC 62443-3-3: System security requirements and security levels
- IEC 62443-4-1 and 4-2: Secure product development lifecycle and technical security requirements for IACS products
-
ISO/IEC 27001: Information security management system standards often integrated with IEC 62443-2-1 security program requirements for holistic organizational security.
Conclusion
IEC 62443-2-1:2024 is essential for industrial asset owners seeking to implement structured, sustainable cybersecurity programs tailored to complex and long-lived automation environments. The standard bridges the gap between technical controls and organizational processes, enabling improved risk management, resilience against cyber threats, and regulatory compliance. By adopting IEC 62443-2-1, organizations can enhance the security posture of their industrial systems and protect critical operational capabilities for the future.
Технические детали
- Технический комитет
- TC 65 - Industrial-process measurement, control and automation
- SKU
- IEC 62443-2-1:2024
Похожие стандарты
Стандарты, упомянутые в описании
IEC 62443-3-3:2013
ДействующийIndustrial communication networks - Network and system security - Part 3-3: System security requirements and…
Overview IEC 62443-3-3:2013 - Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels - defines detailed technical requirements fo…
IEC 62443-4-1:2018
ДействующийSecurity for industrial automation and control systems - Part 4-1: Secure product development lifecycle requi…
Overview IEC 62443-4-1:2018, published by the International Electrotechnical Commission (IEC), establishes process requirements for the secure development of products used in industrial automation an…
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
IEC 62443-2-1:2010
ДействующийIndustrial communication networks - Network and system security - Part 2-1: Establishing an industrial automa…
Overview IEC 62443-2-1:2010 specifies the elements required to establish a Cyber Security Management System (CSMS) for Industrial Automation and Control Systems (IACS). Part of the IEC 62443 series o…