IEC TS 62443-6-2:2025
Security for industrial automation and control systems - Part 6-2: Security evaluation methodology for IEC 62443-4-2
Security for industrial automation and control systems - Part 6-2: Security evaluation methodology for IEC 62443-4-2
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 62
- Дата публикации:
- 21 января 2025 г.
- Издание:
- IEC TS 62443 edition 1 version 1
- ICS:
- 25.040.40
IEC TS 62443-6-2:2025 specifies the evaluation methodology to support achieving repeatable and reproducible evaluation results for IACS components under evaluation against IEC 62443-4-2 requirements. This document does not specify the definition of a complete certification scheme or certification program. This document does not specify the process evaluations of the secure development lifecycle according to IEC 62443‑4‑1. The existing secure development lifecycle according to IEC 62443‑4‑1 is a prerequisite in this evaluation methodology. This document does not specify particular tools, e.g. for the use in vulnerability or penetration testing. This document does not focus on lACS components which were not developed according to the lifecycle process of IEC 62443‑4‑1.
Abstract
Overview
IEC TS 62443-6-2:2025, published by the International Electrotechnical Commission (IEC), provides a dedicated security evaluation methodology for Industrial Automation and Control Systems (IACS) components assessed against IEC 62443-4-2. This technical specification aims to achieve repeatable, comparable, and reproducible evaluation results when determining conformity of IACS components with relevant security requirements.
IEC TS 62443-6-2:2025 is specifically designed to be used by evaluators such as vendors, asset owners, and third-party assessors to ensure systematic security assessments of IACS products. While it guides the evaluation process and criteria, it does not define a complete certification scheme or specify tool selection for tasks like vulnerability or penetration testing. Moreover, it presumes that the secure development lifecycle as defined in IEC 62443-4-1 has already been followed.
By providing a consistent evaluation approach, IEC TS 62443-6-2:2025 supports organizations in demonstrating compliance and advancing cybersecurity in industrial environments.
Key Topics
- Evaluation Methodology for IACS Components
- Ensures repeatable and reproducible results against IEC 62443-4-2 requirements.
- Covers evaluation requirements, activities, and evidences (artefacts) needed.
- Security Context and Threat Modeling
- Establishes the necessity for documented security context and threat models as foundational steps in evaluation.
- Component Security Requirements
- Includes assessment of common component security constraints (CCSCs) and technical requirements.
- Addresses handling of compensating countermeasures and application of the least privilege principle.
- Evaluation Steps
- Step 1: Assesses security context, threat model, and requirement selection.
- Step 2: Reviews component artefacts for evidence of security processes and compliance.
- Evaluation Activities and Criteria
- Systematically verifies requirements such as identification/authentication control, use control, system integrity, data confidentiality, and other critical cybersecurity aspects.
- Evaluation Reporting
- Sets out guidelines for evaluation documentation and reporting, ensuring transparency and comparability.
Applications
IEC TS 62443-6-2:2025 is of high practical value for stakeholders involved in the design, development, procurement, and assessment of IACS components, specifically:
- Product Manufacturers and Developers
- Ensure their components conform to IEC 62443-4-2 requirements and are ready for rigorous third-party evaluation.
- Prepare necessary evidence and documentation, such as security contexts, threat models, design documents, and testing reports.
- Asset Owners and Operators
- Request or perform security evaluations on new and existing IACS components using a transparent and consistent approach.
- Make informed procurement decisions based on reproducible assessment results.
- Certification and Evaluation Bodies
- Use the standardized methodology to deliver impartial, repeatable assessment outcomes.
- Align evaluation practices with recognized global standards for industrial cybersecurity.
- System Integrators
- Understand and document any compensating countermeasures required at system integration level to support component compliance.
This standard is a core resource for organizations working towards robust cybersecurity postures for industrial automation and control systems, especially in process industries, manufacturing, utilities, and infrastructure.
Related Standards
Organizations and professionals using IEC TS 62443-6-2:2025 should be familiar with key related standards in the IEC 62443 series:
- IEC 62443-4-2:2019
Security for industrial automation and control systems - Technical security requirements for IACS components. - IEC 62443-4-1:2018
Security for industrial automation and control systems - Secure product development lifecycle requirements. - IEC 62443-1-1 to 62443-3-3
Foundational requirements and general concepts for IACS security. - ISO/IEC 17000 Series
Standards covering conformity assessment vocabulary and principles.
Referencing and applying these standards in conjunction with IEC TS 62443-6-2:2025 supports comprehensive, harmonized approaches to industrial cybersecurity evaluations and compliance.
Explore IEC TS 62443-6-2:2025 to bring rigor and repeatability to your IACS component security assessments, strengthening trust and resilience in your industrial automation environment.
Технические детали
- Технический комитет
- TC 65 - Industrial-process measurement, control and automation
- SKU
- IEC TS 62443-6-2:2025
Похожие стандарты
Стандарты, упомянутые в описании
IEC 62443-4-2:2019
ДействующийSecurity for industrial automation and control systems - Part 4-2: Technical security requirements for IACS c…
Overview IEC 62443-4-2:2019 is an international standard published by the International Electrotechnical Commission (IEC) that specifies the technical security requirements for Industrial Automation…
IEC 62443-4-1:2018
ДействующийSecurity for industrial automation and control systems - Part 4-1: Secure product development lifecycle requi…
Overview IEC 62443-4-1:2018, published by the International Electrotechnical Commission (IEC), establishes process requirements for the secure development of products used in industrial automation an…
IEC 62443-3-3:2013
ДействующийIndustrial communication networks - Network and system security - Part 3-3: System security requirements and…
Overview IEC 62443-3-3:2013 - Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels - defines detailed technical requirements fo…