Insights / ISA/IEC 62443

IEC 62443: From Security Levels to Real OT Security

Security levels are not a number you pick. They come from the risk, the consequences of compromise, and an honest measurement of what is actually in place today. Here is the path we walk with plant operators.

Cesar GiraldoPotenza Services, Inc.

SL-T Target
The level a zone needs, set by risk assessment.
SL-C Capability
The level your systems are designed to reach.
SL-A Achieved
The level actually in place right now.

The Eight-Step Path

Every step feeds the next. Steps four and five are where most programs go wrong: they set a target and never measure reality against it.

  1. 1

    Start with the Risk

    • What are we protecting?
    • What happens if it is compromised?
    • What threat are we facing?
  2. 2

    Assess the Environment

    • How capable are existing systems?
    • What controls exist already?
    • Where are the gaps?
  3. 3

    Target Security Level

    SL-T

    Derived from the risk and the consequences of compromise.

  4. 4

    Achieved Security Level

    SL-A

    What is actually in place today: configuration, patching, and operational practice.

  5. 5

    Gap Analysis

    Compare SL-T against SL-A. Identify the gaps between target and reality.

  6. 6

    Requirements and Controls

    Define and select the right controls to close each gap.

  7. 7

    Implementation

    Deploy the controls and update the architecture.

  8. 8

    Verification

    Verify effectiveness, re-measure SL-A, and continuously improve.

Example OT Environment

Zones group assets that share a security level. Conduits are the controlled paths between them.

  1. Internet
  2. Remote Access (Controlled)
  3. Enterprise Network
  4. DMZ
  5. Operations Network

Zone: Site Business

  • Business Systems
  • Applications

Zone: Operations

  • Historian
  • HMI
  • Engineering Workstation

Zone: Control

  • SCADA
  • PLC
  • RTU
  • I/O Devices

Zone: Process

  • Sensors
  • Actuators
  • Field Devices
  • Robots
  • Process Equipment

Where the Capability Comes From

  • From the Component

    Built-in security features in devices and systems: a component's SL-C.

  • From the Network Architecture

    Segmentation, firewalls, zones and conduits.

  • From a Combination

    Technical and organizational controls working together to reach SL-A.

Use the Right Controls

  • Network Segmentation (Zones and Conduits)
  • Firewalls
  • Controlled Remote Access
  • Jump Servers
  • Strong Authentication
  • Monitoring and Logging
  • Vulnerability and Patch Management
  • Backup and Recovery
  • Compensating Controls

Key Principle

The security level is driven by the risk and the required security capability, not simply selected as a target number.

  • Reduce Risk
  • Protect Operations
  • Improve Resilience
  • Ensure Compliance
  • Deliver Long-Term Value

Pick your SL-T from risk, measure your SL-A honestly, and close the gap with the right controls. That is a real OT security program, not a number on a page.

Not sure what your SL-A actually is?

We measure it on site, zone by zone, and hand you the gap analysis against the target your risk demands. OEM-independent, no platform to sell.

Agende una Conversación

Start with the readiness assessment

Ten minutes, no email required. It tells you which of the eight steps your plant is stuck on.

Take the Assessment