Scope: This part of the IEC 62443 series provides detailed technical control system requirements (SRs) associated with the seven foundational requirements (FRs) described in IEC 62443-1-1 including defining the requirements for control system capability security levels, SL-C (control system). These requirements would be used by various members of the industrial automation and control system (IACS) community along with the defined zones and conduits for the system under consideration (SuC) while developing the appropriate control system target SL, SL-T (control system), for a specific asset.
As defined in IEC 62443-1-1 there are a total of seven FRs:a) Identification and authentication control (IAC),b) Use control (UC),c) System integrity (SI),d) Data confidentiality (DC),e) Restricted data flow (RDF),f) Timely response to events (TRE), andg) Resource availability (RA).
These seven requirements are the foundation for control system capability SLs, SL-C (control system). Defining security capability at the control system level is the goal and objective of this standard as opposed to target SLs, SL-T, or achieved SLs, SL-A, which are out of scope.
See IEC 62443-2-1 for an equivalent set of non-technical, program-related, capability SRs necessary for fully achieving a control system target SL.Cross References:IEC/TS 62443-1-1:2009IEC 62443-2-1EN IEC 62443-4-1IEC 62443-4-1EN IEC 62443-4-2ISO/IEC 27002IEC 62443-4-2EN ISO/IEC 27002EN IEC 62443-2-4IEC 62443-2-4Incorporates the following:Corrigendum, May 2019; Corrigendum, May 2014