IEC 62443-4-2 Component Security Requirements
IEC 62443-4-2 defines the technical security capabilities that individual industrial automation and control components, such as controllers, workstations, software applications and network devices, must provide for each security level.
IEC 62443-4-2, Technical security requirements for IACS components, specifies the security capabilities that individual products must provide to support a given security level. Requirements are organised under the seven foundational requirements and define component capability security levels from 1 to 4. The standard covers four component types: software applications, embedded devices such as PLCs and controllers, host devices such as workstations and servers, and network devices such as switches, routers and firewalls.
Product suppliers use IEC 62443-4-2 to design and declare the security capabilities of controllers, gateways, HMIs and network equipment, and asset owners and integrators use it to select products that can meet the target security level of the zone where they will be installed. Requirements include unique user and device authentication, role-based authorisation, software integrity verification, audit logging, secure communications, denial-of-service resilience and backup and restore. Products can be certified against the standard through schemes such as ISASecure.
Component capability is necessary but not sufficient: the achieved security of a plant still depends on configuration, zone design and procedures. The standard assumes that components are developed under a secure development process in line with IEC 62443-4-1. Older products often lack capabilities such as strong authentication or signed firmware, which is why compensating countermeasures and lifecycle replacement plans are part of OT security programmes.
Key points
- Covers software applications, embedded devices, host devices and network devices
- Component requirements map to the seven foundational requirements
- Defines component capability security levels from 1 to 4
- Assumes development under an IEC 62443-4-1 secure development process
Where AiVibe comes in
In AiVibe's AiAmbA AI Factory, the AiAmbA IoT edge layer keeps writes to machines deny-by-default and AI agents only propose changes that a trained operator confirms. AiVibe's security services include vulnerability assessment and penetration testing, and AiVibe is ISO/IEC 27001:2022 certified.
Related terms
- IEC 62443 (ISA/IEC 62443)OT & Industrial Cybersecurity
- IEC 62443-4-1 Secure Product Development LifecycleOT & Industrial Cybersecurity
- IEC 62443-3-3 System Security RequirementsOT & Industrial Cybersecurity
- IEC 62443 Security Levels (SL)OT & Industrial Cybersecurity
- ISASecure CertificationOT & Industrial Cybersecurity
- IEC 62443 Foundational Requirements (FR)OT & Industrial Cybersecurity