Overview
IEC PAS 62443-2-2:2025 - "Security for industrial automation and control systems – Part 2-2: IACS security protection scheme" - provides guidance for developing, validating, operating and maintaining a coordinated set of technical, physical and process security measures called a Security Protection Scheme (SPS). Targeted at asset owners implementing an IACS Security Program (SP), the PAS explains how to apply IEC 62443 series content to manage cyber risks to Industrial Automation and Control Systems (IACS) during the operation phase.
Keywords: IEC PAS 62443-2-2, IACS security protection scheme, SPS, industrial control systems, OT security, asset owner, cybersecurity.
Key Topics
- Scope and lifecycle: Guidance covers SPS generation, validation, operation and periodic revalidation across the IACS life cycle.
- Security Protection Ratings (SPR) and Security Levels (SL): Methods for assigning and predicting SPR values; linkage to SL concepts and use of a maturity model (referencing IEC 62443-2-1) are described.
- Process steps and roles: Defined process steps to generate an SPS and responsibilities for principal roles (asset owner, integration service provider, maintenance service provider, product supplier).
- Cybersecurity Requirement Specification (CRS): Activities and responsibilities for creating CRS documents that drive technical and process measures.
- Validation and verification: Guidance for validating technical, physical and procedural controls, including annexed methodologies for SPR verification and maturity level assessment.
- Views and dashboards: Concepts for visualizing fulfilment of security requirements and SPS status (e.g., generic/system views).
- Annexes: Informative examples for SPR verification methodology and maturity level (ML) assessment to support practical assessment.
Applications
Who uses IEC PAS 62443-2-2 and how:
- Asset owners / operators: Design, document and operate an SPS to ensure ongoing protection of IACS assets and to manage cyber risk during operation.
- Integration and maintenance service providers: Implement technical and process controls according to CRS and support validation and periodic revalidation.
- Product suppliers: Map product capabilities to SLs and participate in SPS validation and evidence provision.
- OT security teams and consultants: Use the SPR/SL mapping, maturity model and verification approaches to evaluate and improve operational security posture.
Practical uses include SPS design, preparing CRS, validating technical measures, conducting SPR assessments, and establishing periodic revalidation processes.
Related Standards
- IEC 62443 series (general framework for IACS security)
- IEC 62443-2-1 (security program maturity model referenced for SPR determination)
IEC PAS 62443-2-2 complements these standards by focusing on how to assemble and maintain an operational Security Protection Scheme for industrial control systems.