OPERATIONAL TECHNOLOGY SECURITY

IEC 62443, Evidenced

Someone has asked you to demonstrate that your industrial control systems are secure. A lender, a regulator, an insurer or a customer. IEC 62443-2-1 is the standard they will point at, and what they want back is not a statement of intent but evidence: the zones, the access controls, the patching decisions, the backups you have actually tested. Auditara turns that into a programme with the evidence pack at the end of it.

What This Is, And What It Is Not

Usually assessed, not certified

Asset owner conformity to IEC 62443-2-1 is most often demonstrated through assessment and evidence rather than an accredited certificate. Where a certification route is required, we will tell you what it involves rather than implying we issue it.

This is the asset owner part

IEC 62443 is a series, not one standard. Part 2-1 covers the security programme an operator runs. Parts 3-2 and 3-3 cover system design and system requirements, and parts 4-1 and 4-2 cover product suppliers. This programme is built for operators.

Designed to sit beside ISO 27001

The 2024 edition deliberately removed duplication with an information security management system. If you hold ISO 27001, this extends it to the operational environment rather than repeating it. Run both in one workspace and the shared governance serves each.

The specialist work stays with specialists

Zones and conduits design, target security level setting and network architecture review are engineering work. Auditara structures the programme and holds the evidence. Where that engineering is needed, it is delivered by an operational technology specialist rather than claimed by us.

What The Programme Covers

Eighty seven requirements across the eight security programme elements the standard defines, each assessed with guidance written for an operational environment rather than an office.

Organisational Security Measures

Ownership, screening, training and physical access, plus how the control environment sits within your wider security management rather than running in parallel to it.

Configuration Management

Asset inventory, current infrastructure documentation, hardened configuration baselines, and change control with a rollback plan. A failed change in a plant is not an inconvenience.

Network And Communications Security

Zones and conduits, segmentation from business networks and from safety systems, network autonomy, wireless, and remote access that is authenticated, monitored and switched off when the work ends.

Component Security

Hardening, dedicated portable media, malware protection where the equipment supports it, and patching validated before it reaches a running system.

Protection Of Data

Classification, confidentiality and integrity, safety system configuration mode, cryptography and key management. In a control environment, integrity usually matters more than secrecy.

User Access Control

The largest element, and where most findings sit. Individual identities, least privilege, authentication, session handling and privilege elevation, designed so a security control never removes an operator's view of the process.

Event And Incident Management

Detection, logging with entries detailed enough to investigate, analysis, and an incident process that answers the question an IT plan never faces: whether to keep running.

System Integrity And Availability

Continuity, resource management, defined failure states, and backups held where an attack on the live environment cannot reach them, with restoration actually tested.

How The Programme Runs

Four phases following the control system security lifecycle, because zoning and target security levels have to be settled before implementation, not alongside it.

Step 1

Book the call

Fifteen minutes with a PECB certified Lead Auditor and Lead Implementer. What has been asked of you, by whom, what operational technology is in scope, and what deadline sits behind it.

Step 2

Establish and assess

Ownership, asset inventory, essential functions, architecture documentation, risk assessment, zones and conduits, and target security levels. Then the gap assessment across all eighty seven requirements.

Step 3

Design and implement

Segmentation, remote access, configuration baselines, access control, data protection, supply chain requirements and personnel security, each tracked with an owner and a date.

Step 4

Operate and monitor

Logging and monitoring, vulnerability and patch handling, access review, and incident response exercised with operations and security in the room together.

Step 5

Sustain and improve

Backup and restoration testing, degraded operating modes, and periodic review with maturity reassessed against the baseline you set at the start.

Step 6

Produce the evidence

Gap report, remediation plan, the programme documents and a scope summary, exported as one pack. Where you also run ISO 27001, both scopes come out in a single package.

Every route starts with a call with a certified ISO 27001 and ISO 42001 Lead Implementer.

Book A Call

Questions

Which part of IEC 62443 does this cover?

Part 2-1, which sets out the security programme requirements for asset owners, in its 2024 edition. That is the part that applies if you operate industrial control systems rather than build or integrate them. Parts 3-2 and 3-3 for zones and system requirements, and 4-1 and 4-2 for product suppliers, are separate.

Do we need to be certified, or is conformity enough?

It depends entirely on what has been asked of you. Financing conditions and customer requirements are frequently written as conformity or alignment rather than certification, which means assessment and evidence rather than an accredited audit cycle. Bring us the exact wording and we will tell you which one you are facing.

We already hold ISO 27001. How much of this is new?

The governance layer largely carries across, which is deliberate on the standard's part. What is new is the operational content: zones and conduits, essential functions, configuration baselines for control devices, patching under outage constraints, and the operating realities that make an IT control dangerous in a plant.

What are zones and conduits?

A zone is a group of assets sharing common security requirements with a clear border. A conduit is the communication path between zones, and it must meet the security level of what it connects. Grouping your environment this way is the organising principle the rest of the standard rests on.

Our equipment is twenty years old and cannot be patched. Does that rule us out?

No. The standard is written for environments where equipment outlives several generations of IT, and it accommodates components that cannot meet a requirement natively. What it expects is that you know which ones, apply compensating measures, and record the residual risk and who accepted it.

Can we run this alongside our ISO 27001 programme in the same workspace?

Yes, and it is the sensible way to do it. Both programmes run in one workspace with shared registers and training records, and the audit package can be exported as a single pack covering both scopes with a summary stating that each framework was assessed against its own control set.

Ready To Get Started?

Book the call. Fifteen minutes, no obligation, and you leave with a route.

See all frameworks