IEC 62443-3-3:2013 PDF
Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels
Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 80
- Дата публикации:
- 7 августа 2013 г.
- Издание:
- IEC IS 62443 edition 1 version 1
- ICS:
- 25.040.40
IEC 62443-3-3:2013 provides detailed technical control system requirements (SRs) associated with the seven foundational requirements (FRs) described in IEC 62443-1-1 including defining the requirements for control system capability security levels, SL-C(control system). These requirements would be used by various members of the industrial automation and control system (IACS) community along with the defined zones and conduits for the system under consideration (SuC) while developing the appropriate control system target SL, SL-T(control system), for a specific asset. The contents of the corrigendum of April 2014 have been included in this copy.
Abstract
Overview
IEC 62443-3-3:2013 - Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels - defines detailed technical requirements for industrial control systems. It maps the seven Foundational Requirements (FRs) introduced in IEC 62443-1-1 to concrete System Requirements (SRs) and describes control system capability security levels (SL‑C) used to derive target security levels (SL‑T) for specific assets and zones/conduits. This edition includes the April 2014 corrigendum.
Keywords: IEC 62443-3-3, industrial cybersecurity, IACS security, control system security, security levels, zones and conduits, SRs, SL‑C, SL‑T.
Key Topics and Technical Requirements
IEC 62443-3-3 provides prescriptive, technical controls to secure IACS components and networks. Key topics covered in the standard include:
-
Identification & Authentication (FR‑1)
- SRs such as SR 1.1 (human user identification and authentication), SR 1.2 (software/device identification), account and authenticator management, PKI certificates and password strength.
-
Use Control (FR‑2)
- Authorization enforcement, session lock/remote session termination, concurrent session control, mobile code and portable device controls.
-
Audit & Accountability (FR‑2 related SRs)
- Auditable events, audit storage capacity, timestamps, response to audit failures, and non‑repudiation mechanisms.
-
Network and System Constraints
- Support of essential functions, compensating countermeasures, least privilege, and controls for wireless and untrusted network access.
-
Security Levels and Requirement Enhancements
- Definition of SL‑C variants and guidance on requirement enhancements per security level to guide design and procurement.
The standard organizes requirements by SR number and provides rationale, supplemental guidance and security level mappings for each SR.
Practical Applications and Who Uses It
IEC 62443-3-3 is intended for the industrial automation and control system (IACS) community and is practically used by:
- Asset owners / operators to define target security levels (SL‑T) for assets, zones and conduits and to set technical baselines.
- System integrators and OT engineers when designing and implementing secure control system architectures and selecting controls that meet SRs.
- Product vendors to build devices and software aligned with SL‑C expectations and to supply documented security features.
- Security architects, auditors and compliance teams for gap analysis, procurement specifications, testing criteria and compliance verification.
Common use cases: zone/conduit design, technical requirement specification in procurement, risk-based selection of controls, and verification of security capabilities for controllers, HMIs and network components.
Related Standards (if applicable)
- IEC 62443 series (e.g., IEC 62443‑1‑1 for FR definitions) - IEC 62443‑3‑3 is part of this suite and works with other parts to provide a comprehensive IACS cybersecurity framework.
- Often used alongside broader IT/IS management standards in governance and compliance programs.
For implementation, consult the full IEC 62443-3-3 document (including corrigendum) and coordinate with other IEC 62443 parts to cover organizational, procedural and system-level requirements.
Технические детали
- Технический комитет
- TC 65 - Industrial-process measurement, control and automation
- SKU
- IEC 62443-3-3:2013
Похожие стандарты
Упомянутые в описании и другие стандарты IEC
IEC 62443-3-3:2013/COR1:2014
ДействующийCorrigendum 1 - Industrial communication networks - Network and system security - Part 3-3: System security r…
IEC 62443-4-2:2019/COR1:2022
ДействующийCorrigendum 1 - Security for industrial automation and control systems - Part 4-2: Technical security require…
IEC 60050-161:1990/AMD2:1998
ДействующийAmendment 2 - International Electrotechnical Vocabulary (IEV) - Part 161: Electromagnetic compatibility
IEC 60050-161:1990/AMD2:1998 – Electromagnetic Compatibility Vocabulary Amendment ### Overview The IEC 60050-161:1990/AMD2:1998 is the second amendment to the International Electrotechnical Vocabular…