Overview
IEC TS 62443-1-1:2009 - "Industrial communication networks - Network and system security - Part 1‑1: Terminology, concepts and models" is a foundational technical specification for Industrial Automation and Control Systems (IACS) security. This IEC technical specification defines common terminology, high‑level concepts and reference models used across the IEC 62443 series. It establishes the conceptual basis for risk assessment, architecture, lifecycle and programmatic approaches to securing industrial networks (including SCADA and process control systems).
Key topics and requirements
IEC/TS 62443‑1‑1:2009 organizes essential concepts and models that practitioners must understand before applying detailed requirements. Key topics include:
- Terminology and definitions for IACS security to ensure consistent communication across stakeholders.
- Security objectives and foundational requirements that align industrial goals (safety, availability, integrity) with cybersecurity controls.
- Defence‑in‑depth and security context models that guide layered protection of control networks.
- Threat‑risk assessment concepts: asset identification, vulnerabilities, threats, potential impacts and countermeasures.
- Security zones and conduits model for segmenting assets and defining permitted interactions between zones.
- Security levels (SL) and the lifecycle for assessing, implementing and maintaining required SL(achieved).
- Asset and reference models, including examples for SCADA and process manufacturing, to support architecture and design decisions.
- Security program maturity and policy guidance covering enterprise and operational policies, procedures and lifecycle considerations.
Note: IEC TS 62443‑1‑1 focuses on terminology, concepts and models rather than prescriptive technical controls; it sets the framework used by the rest of the IEC 62443 family.
Applications and who uses it
IEC TS 62443‑1‑1:2009 is used by organizations that design, operate or secure industrial control systems:
- Asset owners / operators (utilities, manufacturing, oil & gas) for program planning and risk communication.
- Control systems engineers and system integrators for architecture and segmentation decisions.
- Cybersecurity teams and risk assessors for aligning industrial risk assessments with IACS concepts.
- Vendors and product developers to ensure device and system designs conform to industry models.
- Auditors and consultants as a common reference when mapping requirements from higher‑level standards into IACS contexts.
Practical uses include establishing zone/conduit architectures, scoping risk assessments, defining security policies, and educating stakeholders on industrial cybersecurity terminology and concepts.
Related standards
- IEC 62443 series (other parts covering system, component and organizational requirements)
- ISA/IEC 62443 (industry collaboration)
- Complementary information security standards (e.g., ISO/IEC 27001) for enterprise governance integration
Keywords: IEC TS 62443-1-1:2009, IACS security, industrial communication networks, terminology concepts models, security zones and conduits, threat-risk assessment, defence in depth, SCADA security.