What is IEC 62443?
The international series of standards for the security of industrial automation and control systems. It divides an environment into zones and conduits, and it defines security levels for each. Unlike frameworks written for corporate IT, it assumes an environment where availability and safety lead, which makes it the usual reference for the operational technology side of a mixed estate.
Zones and conduits
The series divides an environment into zones — groups of assets sharing security requirements — and conduits, the communication paths between them. Security levels are then assigned per zone according to the threat it must withstand.
This is the part that transfers least well from IT frameworks, and it is the reason IEC 62443 tends to fit control estates better than control sets written for corporate networks.
Why it suits OT
It assumes an environment where availability and safety lead, where equipment has a long service life, and where the asset owner, the integrator and the product supplier each carry part of the responsibility. Frameworks written for corporate IT generally assume none of those things.
Read more
- The Essential Eight Is Being Retired: What It Means for Your CIRMP Nomination
ASD will retire the Essential Eight within about two years, replacing it with a domain-split Essentials series that includes an operational technology chapter. The Enhanced CIRMP Rules give you until June 2028 to comply with a nominated framework. Those two clocks overlap, and it changes what you should nominate.
See also
- OT Operational Technology Hardware and software that detects or causes changes through direct monitoring or control of physical devices, processes, and events.
- SCADA Supervisory Control and Data Acquisition A control system architecture used to monitor and control geographically distributed industrial processes.
- E8 Essential Eight Eight mitigation strategies published by the Australian Signals Directorate: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups.
O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.