ISA/IEC 62443 · Standards and security levels
Industrial cyber security, translated into action.
Cyvian helps asset owners, operators and organisations understand their position against applicable ISA/IEC 62443 requirements and establish practical, risk-based improvement programmes.
- ISA/IEC 62443 gap assessments
- Zones and conduits
- OT security risk assessment
- Security requirements and target levels
- Governance and asset-owner requirements
- Remediation and improvement planning
- 1Enterprise zoneBusiness systems and corporate networks
- 2Demilitarised zoneControlled exchange between enterprise and control systems
- 3Control zoneSupervisory and control systems
- 4Safety zoneInstrumented protection and the process itself
- 5ConduitsDefined, controlled paths between zones
The standard, in parts
Which part applies to you
ISA/IEC 62443 is a family of standards covering asset owners, service providers, system design and product development. Cyvian works with the parts that apply to your role.
- 2-1
IEC 62443-2-1
Security programmes for IACS asset owners.
- 2-4
IEC 62443-2-4
Security requirements for IACS service providers.
- 3-2
IEC 62443-3-2
Security risk assessment and system design.
- 3-3
IEC 62443-3-3
System security requirements and security levels.
- 4-1 / 4-2
IEC 62443-4-1 / 4-2
Secure product development and component requirements.
From assessment to assurance
Assess, identify gaps, prioritise, remediate, assure.
The standard describes requirements. The work is deciding which of them apply, where you stand against them, and what to do first. That is where an improvement programme is won or lost.
- 01
Assess
Establish the current position against applicable requirements.
- 02
Identify gaps
Set out where controls fall short of the requirement.
- 03
Prioritise
Order the work by risk, not by clause number.
- 04
Remediate
Support the improvement programme through delivery.
- 05
Assure
Re-measure and evidence the improvement.
Honest scope
Cyvian assesses against ISA/IEC 62443 and supports alignment with it. We do not issue certification.
Assessment work is carried out with the operational environment in mind: safety, availability and production come first, and improvement plans are built to be delivered inside real maintenance windows.
Across multiple sitesGlobal & multi-site assessments One consistent method across facilities, countries and regions.Standards-led. Risk-focused.
Start with where you actually stand.
A gap assessment against the applicable parts of ISA/IEC 62443 gives you a defensible starting position, a prioritised plan and something to measure progress against.
Discuss ISA/IEC 62443Your enquiry opens with this topic selected. You can change it before sending.
Continue exploring