IEC 62443-3-2 Security Risk Assessment
IEC 62443-3-2 is the part of the IEC 62443 series that defines how to assess cybersecurity risk for an industrial control system and use the results to partition it into zones and conduits with target security levels.
IEC 62443-3-2, Security risk assessment for system design, defines how asset owners and integrators assess cybersecurity risk for an industrial automation and control system and turn the results into a zone and conduit design with target security levels. It sets out a sequence of zone and conduit requirements, starting with identifying the system under consideration, followed by an initial risk assessment, partitioning into zones and conduits and a detailed risk assessment where initial risk exceeds tolerable risk.
The detailed assessment identifies threats, vulnerabilities and consequences, estimates likelihood and unmitigated risk, assigns target security levels and selects countermeasures until residual risk is tolerable. The outcome is documented in a cybersecurity requirements specification, which describes the zones, conduits, target levels, assumptions and constraints and is approved by the asset owner. This specification is then used to design, procure and verify the system against IEC 62443-3-3.
The assessment draws on process hazard analyses and consequence knowledge from operations, since the worst outcomes in OT are physical. It should be repeated when the system, threat landscape or business use changes. Common challenges are incomplete asset inventories, unclear risk tolerance and treating the exercise as a one-off document rather than a living input to design and change management.
Key points
- Starts by identifying the system under consideration and its boundary
- Partitions the system into zones and conduits after an initial risk assessment
- A detailed assessment assigns target security levels and selects countermeasures
- Results are documented in a cybersecurity requirements specification
Where AiVibe comes in
In AiVibe's AiAmbA AI Factory, the AiAmbA IoT edge layer keeps writes to machines deny-by-default and AI agents only propose changes that a trained operator confirms. AiVibe's security services include vulnerability assessment and penetration testing, and AiVibe is ISO/IEC 27001:2022 certified.
Related terms
- IEC 62443 (ISA/IEC 62443)OT & Industrial Cybersecurity
- Zones and ConduitsOT & Industrial Cybersecurity
- IEC 62443 Security Levels (SL)OT & Industrial Cybersecurity
- IEC 62443-3-3 System Security RequirementsOT & Industrial Cybersecurity
- Industrial Automation and Control System (IACS)OT & Industrial Cybersecurity
- Safety and Security InterplayOT & Industrial Cybersecurity