IEC 62443-3-3:2013
Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels
Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 80
- Дата публикации:
- 7 августа 2013 г.
- Издание:
- IEC IS 62443 edition 1 version 1
- ICS:
- 25.040.40
IEC 62443-3-3:2013 provides detailed technical control system requirements (SRs) associated with the seven foundational requirements (FRs) described in IEC 62443-1-1 including defining the requirements for control system capability security levels, SL-C(control system). These requirements would be used by various members of the industrial automation and control system (IACS) community along with the defined zones and conduits for the system under consideration (SuC) while developing the appropriate control system target SL, SL-T(control system), for a specific asset. The contents of the corrigendum of April 2014 have been included in this copy.
Abstract
Overview
IEC 62443-3-3:2013 - Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels - defines detailed technical requirements for industrial control systems. It maps the seven Foundational Requirements (FRs) introduced in IEC 62443-1-1 to concrete System Requirements (SRs) and describes control system capability security levels (SL‑C) used to derive target security levels (SL‑T) for specific assets and zones/conduits. This edition includes the April 2014 corrigendum.
Keywords: IEC 62443-3-3, industrial cybersecurity, IACS security, control system security, security levels, zones and conduits, SRs, SL‑C, SL‑T.
Key Topics and Technical Requirements
IEC 62443-3-3 provides prescriptive, technical controls to secure IACS components and networks. Key topics covered in the standard include:
-
Identification & Authentication (FR‑1)
- SRs such as SR 1.1 (human user identification and authentication), SR 1.2 (software/device identification), account and authenticator management, PKI certificates and password strength.
-
Use Control (FR‑2)
- Authorization enforcement, session lock/remote session termination, concurrent session control, mobile code and portable device controls.
-
Audit & Accountability (FR‑2 related SRs)
- Auditable events, audit storage capacity, timestamps, response to audit failures, and non‑repudiation mechanisms.
-
Network and System Constraints
- Support of essential functions, compensating countermeasures, least privilege, and controls for wireless and untrusted network access.
-
Security Levels and Requirement Enhancements
- Definition of SL‑C variants and guidance on requirement enhancements per security level to guide design and procurement.
The standard organizes requirements by SR number and provides rationale, supplemental guidance and security level mappings for each SR.
Practical Applications and Who Uses It
IEC 62443-3-3 is intended for the industrial automation and control system (IACS) community and is practically used by:
- Asset owners / operators to define target security levels (SL‑T) for assets, zones and conduits and to set technical baselines.
- System integrators and OT engineers when designing and implementing secure control system architectures and selecting controls that meet SRs.
- Product vendors to build devices and software aligned with SL‑C expectations and to supply documented security features.
- Security architects, auditors and compliance teams for gap analysis, procurement specifications, testing criteria and compliance verification.
Common use cases: zone/conduit design, technical requirement specification in procurement, risk-based selection of controls, and verification of security capabilities for controllers, HMIs and network components.
Related Standards (if applicable)
- IEC 62443 series (e.g., IEC 62443‑1‑1 for FR definitions) - IEC 62443‑3‑3 is part of this suite and works with other parts to provide a comprehensive IACS cybersecurity framework.
- Often used alongside broader IT/IS management standards in governance and compliance programs.
For implementation, consult the full IEC 62443-3-3 document (including corrigendum) and coordinate with other IEC 62443 parts to cover organizational, procedural and system-level requirements.
Технические детали
- Технический комитет
- TC 65 - Industrial-process measurement, control and automation
- SKU
- IEC 62443-3-3:2013
Похожие стандарты
Другие стандарты IEC
IEC 62590-2-2:2026
ДействующийRailway applications - Electronic power converters for fixed installations - Part 2-2: DC Traction applicatio…
Overview IEC 62590-2-2:2026 is an international standard developed by the International Electrotechnical Commission (IEC) focusing on railway applications, specifically the electronic power converter…
IEC 61753-042-02:2026
ДействующийFibre optic interconnecting devices and passive components - Performance standard - Part 042-02: Plug-pigtail…
Overview IEC 61753-042-02:2026 establishes the minimum performance, test, and measurement requirements for plug-pigtail and plug-receptacle style OTDR (Optical Time-Domain Reflectometer) reflecting d…
IEC 61837-2:2018
ДействующийSurface mounted piezoelectric devices for frequency control and selection - Standard outlines and terminal le…
Overview IEC 61837-2:2018 - Surface mounted piezoelectric devices for frequency control and selection - Standard outlines and terminal lead connections - Part 2: Ceramic enclosures (Edition 3.0, 2018…
IEC 61851-23-1:2026
ДействующийElectric vehicle conductive charging system - Part 23-1: DC electric vehicle supply equipment - Automated con…
Overview IEC 61851-23-1:2026 is an international standard published by the International Electrotechnical Commission (IEC) that specifies requirements for DC electric vehicle supply equipment (EVSE)…
IEC 63506:2026
ДействующийCalibration of the prompt fission neutron logging tools
Overview IEC 63506:2026 - Calibration of the Prompt Fission Neutron Logging Tools is the international standard that specifies the calibration methods for prompt fission neutron (PFN) logging tools,…
IEC 63589-1:2026
ДействующийLinear accelerator - Electron linear accelerator for radiation processing - Part 1: General requirements and…
Overview IEC 63589-1:2026 specifies the general requirements and test methods for electron linear accelerator devices used in radiation processing. Developed by the International Electrotechnical Com…
IEC 61837-2:2018/AMD2:2026
ДействующийAmendment 2 - Surface mounted piezoelectric devices for frequency control and selection - Standard outlines a…
Overview IEC 61837-2:2018/AMD2:2026, published by the International Electrotechnical Commission (IEC), serves as Amendment 2 to the international standard for surface mounted piezoelectric devices us…
IEC 61513:2026
ДействующийNuclear power plants - Instrumentation and control important to safety - General requirements for systems
Overview IEC 61513:2026 “Nuclear power plants - Instrumentation and control important to safety - General requirements for systems,” published by the International Electrotechnical Commission (IEC),…