ANSI/ISA-62443-3-2 : 2020
Current
The latest, up-to-date edition.
Security for industrial automation and control systems, Part 3‑2: Security risk assessment for system design
Hardcopy , PDF
English
11-08-2020
ANSI/ISA-62443-3‑2-2020, Security for Industrial Automation and Control Systems – Part 3‑2: Security Risk Assessment for System Design, defines requirements and provides guidance for performing cybersecurity risk assessments specifically for industrial automation and control systems (IACS) during system design. This standard emphasizes risk management tailored to the unique threats, vulnerabilities and consequences relevant to IACS, including safety-related assets, temporary devices, wireless connections and external network access. It establishes processes to identify the system under consideration (SUC), partition it into security zones and conduits based on risk, perform initial and detailed cyber risk assessments, determine target security levels (SL-T) for each zone or conduit and document security requirements in a cybersecurity requirements specification (CRS). It also provides definitions, workflows and examples of risk matrices to guide organizations in aligning security measures with tolerable risk levels and regulatory requirements, supporting clear communication and approval by asset owners.
| DocumentType |
Standard
|
| ISBN |
978-1-64331-116-6
|
| Pages |
40
|
| ProductNote |
This standard is also refer to ISA-62443-3-3
|
| PublisherName |
International Society of Automation
|
| Status |
Current
|
| ANSI/ISA-62443-3-3 (99.03.03):2013 | SECURITY FOR INDUSTRIAL AUTOMATION AND CONTROL SYSTEMS - PART 3-3: SYSTEM SECURITY REQUIREMENTS AND SECURITY LEVELS |
| ANSI/ISA-62443-4-1:2018 | SECURITY FOR INDUSTRIAL AUTOMATION AND CONTROL SYSTEMS - PART 4-1: PRODUCT SECURITY DEVELOPMENT LIFE-CYCLE REQUIREMENTS |
| ANSI/ISA-62443-2-4-2018 | Security for industrial automation and control systems, Part 2-4: Security program requirements for IACS service providers (IEC 62443-2-4:2015+AMD1:2017 CSV, IDT) |
| ISA-TR84.00.09:2024 | Cybersecurity Related to the Safety Lifecycle |
| ANSI/ISA-62443-2-1:2024 | Security for industrial automation and control systems, Part 2-1: Security program requirements for IACS asset owners |