The Structure and Contents of the ISA/IEC 62443 Series

The ISA/IEC 62443 series of standards is made up of 14 work products (Standards, Technical Specifications and Technical Reports) that are logically grouped in four tiers:

Additionally, the 62443 series introduces three roles:

The first tier of the standard (62443-1), named “General”, includes those work products that are general in nature, introducing foundational concepts, models and terms that are used throughout the series. It includes 4 work products:

This first tier is equally relevant to all roles defined by the standard.

Figure 1. ISA/IEC 62443 Tier Structure

The second tier (62443-2), named “Policies and Procedures”, focuses on the people and processes aspects of an effective security program and its scope is that of addressing plant operations. It includes five work products:

This second tier is most relevant to Asset Owners.

The third tier (62443-3), named “System”, focuses on technology-related aspects of security for systems, describing the guiding principles for performing implementation and integration to achieve security. It includes 3 work products:

The fourth tier (62443-4), named “Component”, focuses on specific security-related requirements for products and components, covering both the technical contents of those products and the processes employed to manage them throughout their lifecycle. It includes two work products:

This fourth tier is most relevant to Product Suppliers. It is important to note that the content of Tier 4 was built with the goal of abstracting the component and its features from any specifics pertaining to the final automation project’s implementation (it is focused on the component’s capabilities).