Industrial Automation and Control System (IACS)
An industrial automation and control system (IACS) is the IEC 62443 term for the people, hardware, software and policies involved in operating an industrial process that can affect its safe, secure and reliable operation.
Industrial automation and control system (IACS) is the term used in the IEC 62443 series for the collection of personnel, hardware, software and policies involved in operating an industrial process that can affect its safe, secure and reliable operation. It includes control systems such as PLCs, DCS, SCADA, safety instrumented systems, HMIs, historians and engineering workstations, together with the networks and procedures that tie them together.
The term is broader than ICS or OT in one important respect: it explicitly includes people and processes, not only technology. IEC 62443 also uses the term automation solution for the control system as integrated and installed at a site; the IACS adds the asset owner's operating and maintenance policies and procedures. This helps assign responsibilities between product suppliers, integrators and the asset owner across design, commissioning, operation and decommissioning.
Under IEC 62443-3-2, the first step of a security risk assessment is identifying the system under consideration and its boundary; everything within it is then partitioned into zones and conduits and assigned target security levels. Typical boundary questions include whether laboratory systems, building management, vendor laptops and cloud connections are in scope. A clear boundary also shows which systems fall under OT change management rather than standard IT processes.
Key points
- Defined in IEC 62443 to include personnel and policies, not just technology
- Covers PLCs, DCS, SCADA, safety systems, HMIs, historians and engineering stations
- The IACS adds the asset owner's operating and maintenance procedures to the automation solution
- Defining the system under consideration is the first step in IEC 62443-3-2
Where AiVibe comes in
In AiVibe's AiAmbA AI Factory, the AiAmbA IoT edge layer keeps writes to machines deny-by-default and AI agents only propose changes that a trained operator confirms. AiVibe's security services include vulnerability assessment and penetration testing, and AiVibe is ISO/IEC 27001:2022 certified.
Related terms
- IEC 62443 (ISA/IEC 62443)OT & Industrial Cybersecurity
- IEC 62443-3-2 Security Risk AssessmentOT & Industrial Cybersecurity
- Zones and ConduitsOT & Industrial Cybersecurity
- Operational Technology (OT) SecurityOT & Industrial Cybersecurity
- Programmable Logic Controller (PLC)PLC & Industrial Control
- Supervisory Control and Data Acquisition (SCADA)PLC & Industrial Control