How the series is organised
The series is split into four groups. The general parts (62443-1-x) set the vocabulary and concepts. The policies and procedures parts (62443-2-x) describe the security programme an asset owner runs and what a service provider must do. The system parts (62443-3-x) cover risk assessment, system design and the technical requirements of a control system. The component parts (62443-4-x) are for product suppliers: secure development and product requirements.
An asset owner lives mostly in 62443-2-1 (your security programme), 62443-3-2 (risk assessment and the design of zones and conduits) and 62443-3-3 (the system requirements at each security level). The rest is how you hold your integrators and vendors to account.
Zones and conduits
The central idea is to divide the control system into zones: groups of assets that share the same security requirements because they do the same job and face the same consequences if compromised. A safety system, a turbine controller and an engineering workstation are not the same zone.
A conduit is the communication path between zones. Every conduit is a place where a control can be applied: a firewall, a data diode, a jump host, a protocol filter. Segmentation in 62443 terms is deciding the zones, drawing the conduits and enforcing them.
Security levels
Each zone gets a target security level from 1 to 4. The levels describe the adversary the zone must resist: casual or accidental misuse at level 1; an intentional attacker with low resources and generic skills at level 2; a sophisticated attacker with moderate resources and control-system skills at level 3; a highly resourced, state-level attacker at level 4.
The target level is set by consequence. A zone whose compromise could hurt someone or stop a plant for weeks needs a higher level than a reporting historian. 62443-3-3 then lists the technical requirements a system needs to meet each level, grouped under seven foundational requirements: identification and authentication, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability.
What an assessment produces
- A zone and conduit model of your estate, with each zone's target security level and the reason for it.
- A gap analysis: the achieved level of each zone against its target, requirement by requirement.
- A risk register that ties each gap to a consequence in the plant, not just a control name.
- A prioritised programme: the changes, the order, and what each one buys you.
How it fits the other frameworks
IEC 62443 is a control-system standard, not a governance framework. It sits comfortably under a programme framework such as AESCSF, the NIST Cybersecurity Framework or ISO/IEC 27001, and it is the vocabulary most OT regulators use when they talk about segmentation and trust levels. India's Bureau of Indian Standards has adopted the series as Indian Standards, and the CEA power sector regulations' requirement to segment OT by trust level is a zone-and-conduit design by another name.
- IEC 62443 series, in particular parts 1-1, 2-1, 3-2 and 3-3





