IEC TS 62443-6-1:2024
Security for industrial automation and control systems - Part 6-1: Security evaluation methodology for IEC 62443-2-4
Security for industrial automation and control systems - Part 6-1: Security evaluation methodology for IEC 62443-2-4
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 132
- Дата публикации:
- 12 марта 2024 г.
- Издание:
- IEC TS 62443 edition 1 version 1
- ICS:
- 25.040.40
IEC TS 62443-6-1:2024 specifies the evaluation methodology to support interested parties (e.g. during conformity assessment activities) to achieve repeatable and reproducible evaluation results against IEC 62443-2-4 requirements. This document is intended for first-party, second-party or third-party conformity assessment activity, for example by product suppliers, service providers, asset owners and conformity assessment bodies. NOTE 1 62443-2-4 specifies requirements for security capabilities of an IACS service provider. These security capabilities can be offered as a security program during integration and maintenance of an automation solution. NOTE 2 The term “conformity assessment” and the terms first-party conformity assessment activity, second-party conformity assessment activity and third-party conformity assessment activity are defined in ISO/IEC 17000.
Abstract
Overview
IEC TS 62443-6-1:2024 defines a security evaluation methodology to assess conformity to IEC 62443-2-4 requirements. It provides a structured approach to achieve repeatable and reproducible evaluation results for security programs of Industrial Automation and Control Systems (IACS) service providers. The Technical Specification is intended for first‑party, second‑party and third‑party conformity assessment activities (e.g., product suppliers, service providers, asset owners, conformity assessment bodies).
Keywords: IEC TS 62443-6-1:2024, security evaluation methodology, IEC 62443-2-4, IACS, conformity assessment, security program.
Key Topics
- Scope and purpose: Establishes evaluation steps and evidence expectations to support conformity assessment against IEC 62443-2-4 (security program requirements for IACS service providers).
- Scoping the Subject under Evaluation (SuE): Defines minimum scope information required to start an evaluation (security program, processes, projects, or systems under review).
- Conformity statements and conformance evidence: Guidance on what a conformity statement should contain and examples of acceptable evidence.
- Evaluation process: Systematic methodology covering examination, verification and judgement to generate repeatable verdicts.
- Maturity Levels (ML 1–ML 4): Evaluation criteria and examples of evidence tailored to each maturity level; Clause 5.4 addresses particular requirements for ML‑4.
- Table of evaluation criteria (Table 1): Cross-references requirements to acceptable evaluation criteria and example conformance evidence.
- Terminology and artifacts: Definitions and abbreviations used (e.g., EoE - evidence of existence, PoE - proof of execution, KPI).
Applications
- Service providers: Use the methodology to prepare and demonstrate their security program conformity to IEC 62443-2-4 during bids, audits or certifications.
- Asset owners/operators: Evaluate or audit third‑party service providers’ security programs consistently and objectively.
- Conformity assessment bodies / auditors: Apply the standardized evaluation steps and Table 1 to produce repeatable assessment results.
- Integrators and maintenance teams: Align internal processes and evidence collection (EoE, PoE, KPIs) with the expectations described to meet client requirements.
Practical value: enables consistent, reproducible assessments; clarifies evidence types; supports maturity-based benchmarking and continuous improvement of IACS security programs.
Related Standards
- IEC 62443-2-4:2015 (including AMD1:2017) - normative reference for security program requirements.
- Other parts of the IEC 62443 series - broader guidance on IACS security.
- ISO/IEC 17000 - definitions for conformity assessment terminology referenced in this TS.
For implementers and evaluators, IEC TS 62443-6-1:2024 is a practical companion to IEC 62443-2-4 that standardizes how security programs are scoped, evidenced and judged across ML 1–ML 4.
Технические детали
- Технический комитет
- TC 65 - Industrial-process measurement, control and automation
- SKU
- IEC TS 62443-6-1:2024
Похожие стандарты
Стандарты, упомянутые в описании
IEC 62443-2-4:2023
ДействующийSecurity for industrial automation and control systems - Part 2-4: Security program requirements for IACS ser…
Overview IEC 62443-2-4:2023 is an essential international standard published by the International Electrotechnical Commission (IEC) that defines security program requirements for Industrial Automatio…
IEC 62443-3-3:2013
ДействующийIndustrial communication networks - Network and system security - Part 3-3: System security requirements and…
Overview IEC 62443-3-3:2013 - Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels - defines detailed technical requirements fo…