62443-2-1-AC | Account Management and Access Control for IACS | 0 |
62443-2-1-BCP | Business Continuity and Disaster Recovery for IACS | 1 |
62443-2-1-CSMS | Cyber Security Management System (CSMS) for IACS | 1 |
62443-2-1-IR | Incident Planning and Response for IACS | 1 |
62443-2-1-MOC | Management of Change for IACS Security | 2 |
62443-2-1-NSEG | Network Segmentation and Zone/Conduit Implementation | 1 |
62443-2-1-PHY | Physical and Environmental Security of IACS Assets | 1 |
62443-2-1-PM | Patch Management and System Update for IACS | 1 |
62443-2-1-RA | IACS Risk Identification, Classification and Assessment | 0 |
62443-2-1-TRN | Personnel Security Awareness and Training for IACS | 0 |
62443-2-4-SP-01 | Service Provider Security Program | 1 |
62443-2-4-SP-02 | Service Provider Solution Staffing and Assurance | 0 |
62443-2-4-SP-03 | Service Provider Architecture and Design Practices | 1 |
62443-2-4-SP-04 | Service Provider Wireless and Remote Access Practices | 1 |
62443-2-4-SP-05 | Service Provider Malware Protection Practices | 1 |
62443-2-4-SP-06 | Service Provider Backup and Restore Practices | 1 |
62443-3-2-CRS | Document Cybersecurity Requirements Specification (CRS) | 0 |
62443-3-2-ZCR-1 | Identify System Under Consideration | 0 |
62443-3-2-ZCR-2 | High-Level Risk Assessment | 0 |
62443-3-2-ZCR-3 | Partition the SUC into Zones and Conduits | 1 |
62443-3-2-ZCR-4 | Detailed Cybersecurity Risk Assessment per Zone and Conduit | 0 |
62443-3-3-FR1-SR-1-1 | Human User Identification and Authentication (FR1) | 1 |
62443-3-3-FR1-SR-1-11 | Unsuccessful Login Attempts | 0 |
62443-3-3-FR1-SR-1-2 | Software Process and Device Identification and Authentication | 0 |
62443-3-3-FR1-SR-1-5 | Authenticator Management | 0 |
62443-3-3-FR1-SR-1-7 | Strength of Password-Based Authentication | 0 |
62443-3-3-FR2-SR-2-1 | Authorisation Enforcement (FR2 Use Control) | 0 |
62443-3-3-FR2-SR-2-4 | Mobile Code Restriction | 0 |
62443-3-3-FR2-SR-2-5 | Session Lock and Termination | 1 |
62443-3-3-FR2-SR-2-8 | Auditable Events | 1 |
62443-3-3-FR3-SR-3-1 | Communication Integrity (FR3 System Integrity) | 1 |
62443-3-3-FR3-SR-3-2 | Protection from Malicious Code | 1 |
62443-3-3-FR3-SR-3-3 | Security Functionality Verification | 1 |
62443-3-3-FR3-SR-3-4 | Software and Information Integrity | 0 |
62443-3-3-FR3-SR-3-8 | Session Integrity | 0 |
62443-3-3-FR4-SR-4-1 | Information Confidentiality (FR4 Data Confidentiality) | 1 |
62443-3-3-FR4-SR-4-2 | Information Persistence and Sanitisation | 1 |
62443-3-3-FR5-SR-5-1 | Network Segmentation (FR5 Restricted Data Flow) | 0 |
62443-3-3-FR5-SR-5-2 | Zone Boundary Protection | 0 |
62443-3-3-FR5-SR-5-3 | General-Purpose Person-to-Person Communication Restrictions | 0 |
62443-3-3-FR6-SR-6-1 | Audit Log Accessibility (FR6 Timely Response to Events) | 0 |
62443-3-3-FR6-SR-6-2 | Continuous Monitoring | 1 |
62443-3-3-FR7-SR-7-1 | Denial-of-Service Protection (FR7 Resource Availability) | 1 |
62443-3-3-FR7-SR-7-3 | Control System Backup | 1 |
62443-3-3-FR7-SR-7-6 | Network and Security Configurations | 0 |
62443-4-1-DM | Defect Management and Vulnerability Handling | 0 |
62443-4-1-SD | Secure by Design | 0 |
62443-4-1-SG | Security Guidelines for Asset Owner | 0 |
62443-4-1-SI | Secure Implementation | 0 |
62443-4-1-SM | Security Management (Product Development) | 1 |
62443-4-1-SR | Specification of Security Requirements | 0 |
62443-4-1-SUM | Security Update Management | 1 |
62443-4-1-SVV | Security Verification and Validation | 0 |
62443-4-2-CR-1-1 | Component Identification and Authentication of Users | 0 |
62443-4-2-CR-3-1 | Component Communication Integrity | 0 |
62443-4-2-CR-7-1 | Component Denial-of-Service Protection | 1 |
62443-4-2-EDR-3-10 | Embedded Device Support for Updates | 1 |
IEC62443-01 | Critical asset identification and inventory | 0 |
IEC62443-02 | System security categorization | 45 |
IEC62443-03 | Security governance structure | 0 |
IEC62443-04 | Roles and responsibilities for critical systems | 1 |
IEC62443-05 | Security policy for operational technology | 8 |
IEC62443-06 | Physical and logical access controls | 0 |
IEC62443-07 | Personnel risk assessment | 171 |
IEC62443-08 | Electronic access perimeter management | 102 |
IEC62443-09 | Interactive remote access security | 0 |
IEC62443-10 | Revocation of access procedures | 102 |
IEC62443-11 | Security patch management for OT | 15 |
IEC62443-12 | Malware prevention for operational systems | 30 |
IEC62443-13 | Network security monitoring | 77 |
IEC62443-14 | System security hardening | 45 |
IEC62443-15 | Ports and services management | 0 |
IEC62443-16 | Incident response plan for operational disruptions | 142 |
IEC62443-17 | Recovery plan for critical systems | 142 |
IEC62443-18 | Reporting obligations to authorities | 13 |
IEC62443-19 | Coordination with sector-specific agencies | 0 |
IEC62443-20 | Exercises and drills for OT incidents | 142 |
IEC62443-21 | Supply chain risk management for critical components | 110 |
IEC62443-22 | Configuration management for OT systems | 92 |
IEC62443-23 | Change management procedures | 88 |
IEC62443-24 | Vulnerability assessment for critical systems | 130 |
2-4 SP | Service provider capability requirements by functional area | 0 |
3-2 ZCR | Zone and conduit requirements: the risk assessment workflow | 0 |
3-3 FR 1 | FR 1: Identification and authentication control (IAC) | 0 |
3-3 FR 2 | FR 2: Use control (UC) | 0 |
3-3 FR 3 | FR 3: System integrity (SI) | 0 |
3-3 FR 4 | FR 4: Data confidentiality (DC) | 0 |
3-3 FR 5 | FR 5: Restricted data flow (RDF) | 0 |
3-3 FR 6 | FR 6: Timely response to events (TRE) | 0 |
3-3 FR 7 | FR 7: Resource availability (RA) | 0 |
4-1 DM | Practice 6: Management of security-related issues | 0 |
4-1 SD | Practice 3: Secure by design | 0 |
4-1 SG | Practice 8: Security guidelines | 0 |
4-1 SI | Practice 4: Secure implementation | 0 |
4-1 SM | Practice 1: Security management | 0 |
4-1 SR | Practice 2: Specification of security requirements | 0 |
4-1 SUM | Practice 7: Security update management | 0 |
4-1 SVV | Practice 5: Security verification and validation testing | 0 |
4-2 FR 1 | FR 1: Identification and authentication control (IAC) (component requirements) | 0 |
4-2 FR 2 | FR 2: Use control (UC) (component requirements) | 0 |
4-2 FR 3 | FR 3: System integrity (SI) (component requirements) | 0 |
4-2 FR 4 | FR 4: Data confidentiality (DC) (component requirements) | 0 |
4-2 FR 5 | FR 5: Restricted data flow (RDF) (component requirements) | 0 |
4-2 FR 6 | FR 6: Timely response to events (TRE) (component requirements) | 0 |
4-2 FR 7 | FR 7: Resource availability (RA) (component requirements) | 0 |
AVAIL 1.1 | Continuity management | 0 |
AVAIL 1.2 | Resource availability management | 0 |
AVAIL 1.3 | Failure-state | 0 |
AVAIL 2.1 | Backup | 0 |
AVAIL 2.2 | Backup non-interference | 0 |
AVAIL 2.3 | Backup verification | 0 |
AVAIL 2.4 | Backup media | 0 |
AVAIL 2.5 | Backup restoration | 0 |
CM 1.1 | Asset inventory baseline | 0 |
CM 1.2 | Infrastructure drawings/documentation | 0 |
CM 1.3 | Configuration settings | 0 |
CM 1.4 | Change control | 0 |
COMP 1.1 | Component hardening | 0 |
COMP 1.2 | Dedicated portable media | 0 |
COMP 2.1 | Malware free | 0 |
COMP 2.2 | Malware protection | 0 |
COMP 2.3 | Malware protection software validation and installation | 0 |
COMP 3.1 | Security patch authenticity/integrity | 0 |
COMP 3.2 | Security patch validation and installation | 0 |
COMP 3.3 | Security patch status | 0 |
COMP 3.4 | Security patching retention of security | 0 |
COMP 3.5 | Security patch mitigation | 0 |
CR 1.1 | Human user identification and authentication | 0 |
CR 1.10 | Authenticator feedback | 0 |
CR 1.11 | Unsuccessful login attempts | 0 |
CR 1.12 | System use notification | 0 |
CR 1.14 | Strength of symmetric key-based authentication | 0 |
CR 1.2 | Software process and device identification and authentication | 0 |
CR 1.3 | Account management | 0 |
CR 1.4 | Identifier management | 0 |
CR 1.5 | Authenticator management | 0 |
CR 1.7 | Strength of password-based authentication | 0 |
CR 1.8 | Public key infrastructure certificates | 0 |
CR 1.9 | Strength of public key authentication | 0 |
CR 2.1 | Authorization enforcement | 0 |
CR 2.10 | Response to audit processing failures | 0 |
CR 2.11 | Timestamps | 0 |
CR 2.12 | Non-repudiation | 0 |
CR 2.2 | Wireless use control | 0 |
CR 2.3 | Use control for portable and mobile devices | 0 |
CR 2.5 | Session lock | 0 |
CR 2.6 | Remote session termination | 0 |
CR 2.7 | Concurrent session control | 0 |
CR 2.8 | Auditable events | 0 |
CR 2.9 | Audit storage capacity | 0 |
CR 3.1 | Communication integrity | 0 |
CR 3.3 | Security functionality verification | 0 |
CR 3.4 | Software and information integrity | 0 |
CR 3.5 | Input validation | 0 |
CR 3.6 | Deterministic output | 0 |
CR 3.7 | Error handling | 0 |
CR 3.8 | Session integrity | 0 |
CR 3.9 | Protection of audit information | 0 |
CR 4.1 | Information confidentiality | 0 |
CR 4.2 | Information persistence | 0 |
CR 4.3 | Use of cryptography | 0 |
CR 5.1 | Network segmentation | 0 |
CR 6.1 | Audit log accessibility | 0 |
CR 6.2 | Continuous monitoring | 0 |
CR 7.1 | Denial of service protection | 0 |
CR 7.2 | Resource management | 0 |
CR 7.3 | Control system backup | 0 |
CR 7.4 | Control system recovery and reconstitution | 0 |
CR 7.5 | Emergency power | 0 |
CR 7.6 | Network and security configuration settings | 0 |
CR 7.7 | Least functionality | 0 |
CR 7.8 | Control system component inventory | 0 |
DATA 1.1 | Data classification | 0 |
DATA 1.2 | Data confidentiality | 0 |
DATA 1.3 | Safety system configuration mode | 0 |
DATA 1.4 | Data retention policy | 0 |
DATA 1.5 | Cryptographic mechanisms | 0 |
DATA 1.6 | Key management | 0 |
DATA 1.7 | Data Integrity | 0 |
DM-1 | Receiving notifications of security-related issues | 0 |
DM-2 | Reviewing security-related issues | 0 |
DM-3 | Assessing security-related issues | 0 |
DM-4 | Addressing security-related issues | 0 |
DM-5 | Disclosing security-related issues | 0 |
DM-6 | Periodic review of security defect management practice | 0 |
EDR 2.13 | Use of physical diagnostic and test interfaces (embedded device) | 0 |
EDR 2.4 | Mobile code (embedded device) | 0 |
EDR 3.10 | Support for updates (embedded device) | 0 |
EDR 3.11 | Physical tamper resistance and detection (embedded device) | 0 |
EDR 3.12 | Provisioning product supplier roots of trust (embedded device) | 0 |
EDR 3.13 | Provisioning asset owner roots of trust (embedded device) | 0 |
EDR 3.14 | Integrity of the boot process (embedded device) | 0 |
EDR 3.2 | Protection from malicious code (embedded device) | 0 |
EVENT 1.1 | Event detection | 0 |
EVENT 1.2 | Event reporting | 0 |
EVENT 1.3 | Event reporting interfaces | 0 |
EVENT 1.4 | Logging | 0 |
EVENT 1.5 | Log entries | 0 |
EVENT 1.6 | Log access | 0 |
EVENT 1.7 | Event analysis | 0 |
EVENT 1.8 | Incident handling and response | 0 |
EVENT 1.9 | Vulnerability handling | 0 |
HDR 2.13 | Use of physical diagnostic and test interfaces (host device) | 0 |
HDR 2.4 | Mobile code (host device) | 0 |
HDR 3.10 | Support for updates (host device) | 0 |
HDR 3.11 | Physical tamper resistance and detection (host device) | 0 |
HDR 3.12 | Provisioning product supplier roots of trust (host device) | 0 |
HDR 3.13 | Provisioning asset owner roots of trust (host device) | 0 |
HDR 3.14 | Integrity of the boot process (host device) | 0 |
HDR 3.2 | Protection from malicious code (host device) | 0 |
NDR 1.13 | Access via untrusted networks (network device) | 0 |
NDR 1.6 | Wireless access management (network device) | 0 |
NDR 2.13 | Use of physical diagnostic and test interfaces (network device) | 0 |
NDR 2.4 | Mobile code (network device) | 0 |
NDR 3.10 | Support for updates (network device) | 0 |
NDR 3.11 | Physical tamper resistance and detection (network device) | 0 |
NDR 3.12 | Provisioning product supplier roots of trust (network device) | 0 |
NDR 3.13 | Provisioning asset owner roots of trust (network device) | 0 |
NDR 3.14 | Integrity of the boot process (network device) | 0 |
NDR 3.2 | Protection from malicious code (network device) | 0 |
NDR 5.2 | Zone boundary protection (network device) | 0 |
NDR 5.3 | General purpose person-to-person communication restrictions (network device) | 0 |
NET 1.1 | Segmentation from non-IACS zones | 0 |
NET 1.2 | Documentation of zones and network zone interconnections | 0 |
NET 1.3 | Network segmentation from safety systems | 0 |
NET 1.4 | Network autonomy | 0 |
NET 1.5 | Network disconnection from external networks | 0 |
NET 1.6 | Internal network access control | 0 |
NET 1.7 | Network accessible services | 0 |
NET 1.8 | User messaging | 0 |
NET 1.9 | Network time distribution | 0 |
NET 2.1 | Wireless protocols | 0 |
NET 2.2 | Wireless network segmentation | 0 |
NET 2.3 | Wireless properties and addresses | 0 |
NET 3.1 | Remote access applications | 0 |
NET 3.2 | Remote access connections | 0 |
NET 3.3 | Remote access termination | 0 |
ORG 1.1 | Information security management system (ISMS) | 0 |
ORG 1.2 | Background checks | 0 |
ORG 1.3 | Security roles and responsibilities | 0 |
ORG 1.4 | Security awareness training | 0 |
ORG 1.5 | Security responsibilities training | 0 |
ORG 1.6 | Supply chain security | 0 |
ORG 2.1 | Security risk mitigation | 0 |
ORG 2.2 | Processes for discovery of security anomalies | 0 |
ORG 2.3 | Secure development and support | 0 |
ORG 2.4 | SP reviews | 0 |
ORG 3.1 | Physical access control | 0 |
PART-1-1 | IEC 62443-1-1 and TS 1-5: terminology, concepts, models and the scheme for profiles | 0 |
PART-2-2 | IEC PAS 62443-2-2:2025: IACS security protection rating | 0 |
PART-2-3 | IEC TR 62443-2-3:2015: patch management in the IACS environment | 0 |
PART-3-1 | IEC TR 62443-3-1:2009: security technologies for IACS | 0 |
PART-6 | IEC 62443-6-1 and 6-2: security evaluation methodologies | 0 |
SAR 2.4 | Mobile code (software application) | 0 |
SAR 3.2 | Protection from malicious code (software application) | 0 |
SD-1 | Secure design principles | 0 |
SD-2 | Defense in depth design | 0 |
SD-3 | Security design review | 0 |
SD-4 | Secure design best practices | 0 |
SERIES | IEC 62443: the series, its parts and what is held | 0 |
SG-1 | Product defense-in-depth | 0 |
SG-2 | Defense-in-depth measures expected in the environment | 0 |
SG-3 | Security hardening guidelines | 0 |
SG-4 | Secure disposal guidelines | 0 |
SG-5 | Secure operation guidelines | 0 |
SG-6 | Account management guidelines | 0 |
SG-7 | Documentation review | 0 |
SI-1 | Security implementation review | 0 |
SI-2 | Secure coding standards | 0 |
SM-1 | Development process | 0 |
SM-10 | Custom developed components from third-party suppliers | 0 |
SM-11 | Assessing and addressing security-related issues | 0 |
SM-12 | Process verification | 0 |
SM-13 | Continuous improvement | 0 |
SM-2 | Identification of responsibilities | 0 |
SM-3 | Identification of applicability | 0 |
SM-4 | Security expertise | 0 |
SM-5 | Process scoping | 0 |
SM-6 | File integrity | 0 |
SM-7 | Development environment security | 0 |
SM-8 | Controls for private keys | 0 |
SM-9 | Security requirements for externally provided components | 0 |
SP.01 | Solution staffing | 0 |
SP.02 | Assurance | 0 |
SP.03 | Architecture | 0 |
SP.04 | Wireless | 0 |
SP.05 | Safety instrumented systems (SIS) | 0 |
SP.06 | Configuration management | 0 |
SP.07 | Remote access | 0 |
SP.08 | Event management | 0 |
SP.09 | Account management | 0 |
SP.10 | Malware protection | 0 |
SP.11 | Patch management | 0 |
SP.12 | Backup/restore | 0 |
SPE 1 | SPE 1: Organizational security measures | 0 |
SPE 2 | SPE 2: Configuration management | 0 |
SPE 3 | SPE 3: Network and communications security | 0 |
SPE 4 | SPE 4: Component security | 0 |
SPE 5 | SPE 5: Protection of data | 0 |
SPE 6 | SPE 6: User access control | 0 |
SPE 7 | SPE 7: Event and incident management | 0 |
SPE 8 | SPE 8: System integrity and availability | 0 |
SR 1.1 | Human user identification and authentication | 0 |
SR 1.10 | Authenticator feedback | 0 |
SR 1.11 | Unsuccessful login attempts | 0 |
SR 1.12 | System use notification | 0 |
SR 1.13 | Access via untrusted networks | 0 |
SR 1.2 | Software process and device identification and authentication | 0 |
SR 1.3 | Account management | 0 |
SR 1.4 | Identifier management | 0 |
SR 1.5 | Authenticator management | 0 |
SR 1.6 | Wireless access management | 0 |
SR 1.7 | Strength of password-based authentication | 0 |
SR 1.8 | Public key infrastructure (PKI) certificates | 0 |
SR 1.9 | Strength of public key authentication | 0 |
SR 2.1 | Authorization enforcement | 0 |
SR 2.10 | Response to audit processing failures | 0 |
SR 2.11 | Timestamps | 0 |
SR 2.12 | Non-repudiation | 0 |
SR 2.2 | Wireless use control | 0 |
SR 2.3 | Use control for portable and mobile devices | 0 |
SR 2.4 | Mobile code | 0 |
SR 2.5 | Session lock | 0 |
SR 2.6 | Remote session termination | 0 |
SR 2.7 | Concurrent session control | 0 |
SR 2.8 | Auditable events | 0 |
SR 2.9 | Audit storage capacity | 0 |
SR 3.1 | Communication integrity | 0 |
SR 3.2 | Malicious code protection | 0 |
SR 3.3 | Security functionality verification | 0 |
SR 3.4 | Software and information integrity | 0 |
SR 3.5 | Input validation | 0 |
SR 3.6 | Deterministic output | 0 |
SR 3.7 | Error handling | 0 |
SR 3.8 | Session integrity | 0 |
SR 3.9 | Protection of audit information | 0 |
SR 4.1 | Information confidentiality | 0 |
SR 4.2 | Information persistence | 0 |
SR 4.3 | Use of cryptography | 0 |
SR 5.1 | Network segmentation | 0 |
SR 5.2 | Zone boundary protection | 0 |
SR 5.3 | General purpose person-to-person communication restrictions | 0 |
SR 5.4 | Application partitioning | 0 |
SR 6.1 | Audit log accessibility | 0 |
SR 6.2 | Continuous monitoring | 0 |
SR 7.1 | Denial of service protection | 0 |
SR 7.2 | Resource management | 0 |
SR 7.3 | Control system backup | 0 |
SR 7.4 | Control system recovery and reconstitution | 0 |
SR 7.5 | Emergency power | 0 |
SR 7.6 | Network and security configuration settings | 0 |
SR 7.7 | Least functionality | 0 |
SR 7.8 | Control system component inventory | 0 |
SR-1 | Product security context | 0 |
SR-2 | Threat model | 0 |
SR-3 | Product security requirements | 0 |
SR-4 | Product security requirements content | 0 |
SR-5 | Security requirements review | 0 |
STATUS | Editions and the status of the series as held | 0 |
SUM-1 | Security update qualification | 0 |
SUM-2 | Security update documentation | 0 |
SUM-3 | Dependent component or operating system security update | 0 |
SUM-4 | Security update delivery | 0 |
SUM-5 | Timely delivery of security patches | 0 |
SVV-1 | Security requirements testing | 0 |
SVV-2 | Threat mitigation testing | 0 |
SVV-3 | Vulnerability testing | 0 |
SVV-4 | Penetration testing | 0 |
SVV-5 | Independence of testers | 0 |
USER 1.1 | User identity assignment | 0 |
USER 1.10 | Mutual authentication | 0 |
USER 1.11 | Password protection | 0 |
USER 1.12 | Shared and disclosed/compromised passwords | 0 |
USER 1.13 | User login display information | 0 |
USER 1.14 | User login failure displays | 0 |
USER 1.15 | Consecutive login failures | 0 |
USER 1.16 | Session integrity | 0 |
USER 1.17 | Concurrent sessions | 0 |
USER 1.18 | Screen lock | 0 |
USER 1.19 | Component authentication | 0 |
USER 1.2 | User identity removal | 0 |
USER 1.3 | User identity persistence | 0 |
USER 1.4 | Access rights assignment | 0 |
USER 1.5 | Least privilege | 0 |
USER 1.6 | Software service authentication | 0 |
USER 1.7 | Software services interactive login rights | 0 |
USER 1.8 | Human user authentication | 0 |
USER 1.9 | Multifactor authentication (MFA) | 0 |
USER 2.1 | Authorization | 0 |
USER 2.2 | Separation of duties | 0 |
USER 2.3 | Multiple approvals | 0 |
USER 2.4 | Manual elevation of privileges | 0 |
ZCR 1 | Identify the system under consideration | 0 |
ZCR 2 | Perform an initial cyber security risk assessment | 0 |
ZCR 3 | Partition the SUC into zones and conduits | 0 |
ZCR 4 | Compare initial risk to tolerable risk | 0 |
ZCR 5 | Perform a detailed cyber security risk assessment | 0 |
ZCR 6 | Document cyber security requirements, assumptions and constraints | 0 |
ZCR 7 | Asset owner approval | 0 |