Security Level determination in accordance with IEC 62443
Assessment of the security level of machine OT systems
The Security Level is
a question of context
The IEC 62443 standard provides a structured reference for assessing the security of industrial automation and control systems. Applying it to a machine means understanding whether the technical measures adopted are adequate to the operational context and to the potential impacts on the production process. The Security Level determination service enables the effective security level implemented on the machine to be assessed, highlighting design shortcomings, architectural limitations and requirements not met with respect to the IEC 62443 standard.
When is it needed
The service is indicated when:
- The aim is to assess the security level of machine OT systems in a structured manner;
- It is necessary to compare the measures implemented against the IEC 62443 requirements;
- The aim is to identify architectural limitations that may affect operational continuity and reliability;
- A technical reference is required for planning security improvement activities.
How the assessment is carried out
The activity is structured in accordance with IEC 62443-3-3 and IEC 62443-3-2.
- Definition of the OT perimeter of the machine, with mapping of assets, communication networks, control devices and interfaces with external systems;
- Framing of the security context and qualitative assessment of the impacts of security events on machine operation and plant operability;
- Verification of IEC 62443-3-3 requirements, with reference to the seven Foundational Requirements such as identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events and resource availability.
NOTE: The assessment does not include advanced threat actor modelling or exhaustive attack scenario simulations.
What we deliver
At the end of the activity the following is provided:
- Determination of the Security Level achievable by the machine (Capability SL);
- Identification of the required Security Level (Target SL) based on context; Identification of requirements not met;
- Identification of requirements not met;
- Clear and structured technical recommendations for any remediation and security improvement activities.