IEC 62443
Asset owners, integrators and product suppliers of industrial automation and control systems, in every sector.
The international series for control-system security: vocabulary, the asset owner's security programme (2-1), service provider requirements (2-4), risk assessment and zone-and-conduit design (3-2), system requirements by security level (3-3), and product development and component requirements (4-1, 4-2).
Security levels 1 to 4 describe the adversary a zone must resist. Seven foundational requirements group the technical controls.
How we use it. Our design vocabulary. Risk assessments produce a zone and conduit model with target levels; architecture and network work is specified and verified against 3-2 and 3-3.
Read more: IEC 62443 explained for asset owners
NIST SP 800-82 Rev 3
Anyone building or assessing an OT security programme. Published by the US National Institute of Standards and Technology in 2023 as the Guide to Operational Technology Security.
An end-to-end guide: how OT differs from IT, threats and vulnerabilities specific to control systems, risk management, recommended architectures, and an overlay that tailors the SP 800-53 control catalogue to OT.
How we use it. The reference we use for programme structure and for control selection where a client is not bound to a sector framework. Paired with IEC 62443 for the system-level design.
Read more: The Purdue model and OT network segmentation, without the religion
NIST Cybersecurity Framework
Organisations of any size that want a common language for cyber risk with the board. One of the frameworks accepted under Australia's CIRMP rules.
A framework of functions, categories and outcomes, from governing and identifying through protecting, detecting, responding and recovering. Version 2.0 added governance as a function of its own.
How we use it. A programme framework we map OT controls under when a client has adopted it enterprise-wide, so the plant is reported in the same language as the rest of the business.
MITRE ATT&CK for ICS
Defenders and assessors who want to reason from observed adversary behaviour against control systems.
A knowledge base of tactics and techniques used against industrial control systems, drawn from real intrusions. Twelve tactics, ending in the three unique to OT: inhibit response function, impair process control, and impact.
How we use it. The backbone of our threat assessment: which techniques are realistic against your plant, ranked by consequence, and the controls that break the most paths. Also the reference for monitoring use cases.
Read more: How a threat assessment uses MITRE ATT&CK for ICS
ISO/IEC 27001
Organisations running a certified information security management system. Accepted under the CIRMP rules in Australia; named for critical systems in India's CEA power sector regulations (a deferred provision).
The management-system standard: risk assessment, a statement of applicability, controls from Annex A, and continual improvement, audited by a certification body.
How we use it. Where a client's ISMS scope includes the plant, we make sure the OT risks, assets and controls are actually inside it rather than assumed, and we supply the control-system evidence the auditor asks for.