IEC 62443 Security Levels (SL)
IEC 62443 security levels (SL 1 to SL 4) describe how strongly a zone, conduit, system or component resists attack, from casual violation up to sophisticated, well-resourced attackers with IACS-specific skills.
Security levels (SL) in IEC 62443 express how strongly a zone, conduit, system or component resists attack, on a scale from SL 1 to SL 4, with SL 0 meaning no specific requirements. SL 1 protects against casual or coincidental violation; SL 2 against intentional violation using simple means with low resources, generic skills and low motivation; SL 3 against sophisticated means with moderate resources, IACS-specific skills and moderate motivation; and SL 4 against sophisticated means with extended resources, IACS-specific skills and high motivation.
The standard distinguishes three types. The target security level (SL-T) is the level required for a zone or conduit, set through risk assessment. The capability security level (SL-C) is what a component or system can provide when properly configured, and the achieved security level (SL-A) is what the installed solution actually delivers. Asset owners specify target levels in procurement, suppliers declare capability levels for products assessed against IEC 62443-3-3 or 62443-4-2, and assessments compare achieved levels with targets.
Security levels can be expressed as a vector across the seven foundational requirements, because a zone may need strong integrity protection but only modest confidentiality. Higher levels add requirement enhancements and cost more to achieve and maintain, so targets should follow the assessed risk rather than defaulting to the highest level. Where a component cannot reach the target level, compensating countermeasures at zone or conduit level can close the gap.
Key points
- SL 1 to SL 4 rise from casual violation to sophisticated, well-resourced attack
- Target SL is required, capability SL is what a product can provide, achieved SL is delivered
- Levels can be set per foundational requirement as a vector
- Compensating countermeasures can cover gaps between capability and target levels
Where AiVibe comes in
In AiVibe's AiAmbA AI Factory, the AiAmbA IoT edge layer keeps writes to machines deny-by-default and AI agents only propose changes that a trained operator confirms. AiVibe's security services include vulnerability assessment and penetration testing, and AiVibe is ISO/IEC 27001:2022 certified.
Related terms
- IEC 62443 (ISA/IEC 62443)OT & Industrial Cybersecurity
- IEC 62443 Foundational Requirements (FR)OT & Industrial Cybersecurity
- IEC 62443-3-3 System Security RequirementsOT & Industrial Cybersecurity
- IEC 62443-4-2 Component Security RequirementsOT & Industrial Cybersecurity
- Zones and ConduitsOT & Industrial Cybersecurity
- IEC 62443-3-2 Security Risk AssessmentOT & Industrial Cybersecurity