ANSI/ISA 62443-4-2:2018
Current
The latest, up-to-date edition.
Security for industrial automation and control systems, Part 4-2: Technical security requirements for IACS components
Hardcopy , PDF
English
13-08-2018
ANSI/ISA-62443-4-2-2018, Security for Industrial Automation and Control Systems – Part 4-2: Technical Security Requirements for IACS Components, Second Printing, specifies cybersecurity requirements for components within industrial automation and control systems (IACS), covering embedded devices, host devices, network devices and software applications. This standard organizes security into seven foundational areas: identification and authentication, use control, system integrity, data confidentiality, restricted data flow, timely response to events and resource availability. Components are assigned security capability levels that match their ability to address threats of varying sophistication. Technical requirements include enforcing least privilege access, supporting multifactor authentication, protecting against malicious code, validating inputs, managing secure updates, providing tamper resistance and maintaining detailed audit logs with synchronized timestamps. Components may rely on compensating countermeasures when native capabilities are lacking, enabling secure integration within larger systems. This framework aligns component design and integration with control systems' operational demands, emphasizing availability, integrity and confidentiality while preserving essential functions and supporting risk-based security approaches.
| DocumentType |
Standard
|
| ISBN |
978-1-64331-025-1
|
| Pages |
98
|
| PublisherName |
International Society of Automation
|
| Status |
Current
|
| ANSI/ISA-62443-2-4-2018 | Security for industrial automation and control systems, Part 2-4: Security program requirements for IACS service providers (IEC 62443-2-4:2015+AMD1:2017 CSV, IDT) |
| ISA-TR62443-2-2:2025 | Security for industrial automation and control systems – Part 2-2: IACS security protection scheme |
| ANSI/ISA-62443-3-3 (99.03.03):2013 | SECURITY FOR INDUSTRIAL AUTOMATION AND CONTROL SYSTEMS - PART 3-3: SYSTEM SECURITY REQUIREMENTS AND SECURITY LEVELS |
| ANSI/ISA-62443-4-1:2018 | SECURITY FOR INDUSTRIAL AUTOMATION AND CONTROL SYSTEMS - PART 4-1: PRODUCT SECURITY DEVELOPMENT LIFE-CYCLE REQUIREMENTS |
| ISA-TR84.00.09:2024 | Cybersecurity Related to the Safety Lifecycle |
| IEC TR 62443-2-3:2015 | Security for industrial automation and control systems - Part 2-3: Patch management in the IACS environment |
| ISA TR62443-2-3 : 2015 | SECURITY FOR INDUSTRIAL AUTOMATION AND CONTROL SYSTEMS - PART 2-3: PATCH MANAGEMENT IN THE IACS ENVIRONMENT |
| ANSI/ISA-62443-2-1:2024 | Security for industrial automation and control systems, Part 2-1: Security program requirements for IACS asset owners |
| IEC 62443-3-3:2013 | Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels |