IEC 62443: From Security Levels to Real OT Security
Security levels are not a number you pick. They come from the risk, the consequences of compromise, and an honest measurement of what is actually in place today. Here is the path we walk with plant operators.
Cesar GiraldoPotenza Services, Inc.
- SL-T Target
- The level a zone needs, set by risk assessment.
- SL-C Capability
- The level your systems are designed to reach.
- SL-A Achieved
- The level actually in place right now.
The Eight-Step Path
Every step feeds the next. Steps four and five are where most programs go wrong: they set a target and never measure reality against it.
- 1
Start with the Risk
- What are we protecting?
- What happens if it is compromised?
- What threat are we facing?
- 2
Assess the Environment
- How capable are existing systems?
- What controls exist already?
- Where are the gaps?
- 3
Target Security Level
SL-T
Derived from the risk and the consequences of compromise.
- 4
Achieved Security Level
SL-A
What is actually in place today: configuration, patching, and operational practice.
- 5
Gap Analysis
Compare SL-T against SL-A. Identify the gaps between target and reality.
- 6
Requirements and Controls
Define and select the right controls to close each gap.
- 7
Implementation
Deploy the controls and update the architecture.
- 8
Verification
Verify effectiveness, re-measure SL-A, and continuously improve.
Example OT Environment
Zones group assets that share a security level. Conduits are the controlled paths between them.
- Internet
- Remote Access (Controlled)
- Enterprise Network
- DMZ
- Operations Network
Zone: Site Business
- Business Systems
- Applications
Zone: Operations
- Historian
- HMI
- Engineering Workstation
Zone: Control
- SCADA
- PLC
- RTU
- I/O Devices
Zone: Process
- Sensors
- Actuators
- Field Devices
- Robots
- Process Equipment
Where the Capability Comes From
From the Component
Built-in security features in devices and systems: a component's SL-C.
From the Network Architecture
Segmentation, firewalls, zones and conduits.
From a Combination
Technical and organizational controls working together to reach SL-A.
Use the Right Controls
- Network Segmentation (Zones and Conduits)
- Firewalls
- Controlled Remote Access
- Jump Servers
- Strong Authentication
- Monitoring and Logging
- Vulnerability and Patch Management
- Backup and Recovery
- Compensating Controls
Key Principle
The security level is driven by the risk and the required security capability, not simply selected as a target number.
- Reduce Risk
- Protect Operations
- Improve Resilience
- Ensure Compliance
- Deliver Long-Term Value
Pick your SL-T from risk, measure your SL-A honestly, and close the gap with the right controls. That is a real OT security program, not a number on a page.
Not sure what your SL-A actually is?
We measure it on site, zone by zone, and hand you the gap analysis against the target your risk demands. OEM-independent, no platform to sell.
Schedule a ConversationStart with the readiness assessment
Ten minutes, no email required. It tells you which of the eight steps your plant is stuck on.
Take the Assessment