2026-09-21 · KeXinMaterials 編集チーム
IEC 62443 産業サイバーセキュリティ + 保護ケース B2B コンプライアンスガイド
IEC 62443 「産業通信ネットワーク - ネットワーク及びシステムの IT セキュリティ」 は産業用自動化及び制御システム (IACS) サイバーセキュリティのグローバル規格。産業 4.0 / IIoT / SCADA / DCS / OT に重要。セキュリティレベル (SL) 1-4 を定義。NIS 2 (EU 2022/2555) で重要 + 必須エンティティに要求。
IEC 62443 Scope + Series Structure
IEC 62443 published by IEC TC 65. Industrial cybersecurity. Multi-part series covering general + policies + system + component.
IEC 62443: "Industrial communication networks - IT security for networks and systems". Published by IEC. TC 65 (Industrial process measurement and control).
IEC 62443 series structure: General (62443-1-x), Policies and Procedures (62443-2-x), System Requirements (62443-3-x), Component Requirements (62443-4-x).
IEC 62443-1-1: Terminology, concepts and models. Defines IACS, Security Level (SL), zone, conduit, security context.
IEC 62443-1-2: Glossary of terms. Common reference for all series.
IEC 62443-1-3: System security compliance metrics. Quantitative metrics for security level assessment.
IEC 62443-1-4: IACS security life cycle. Integration with IEC 62443-2-4 service provider requirements.
IEC 62443-2-1: Establishing an IACS security program. Required for asset owners / system integrators.
IEC 62443-2-2: IACS security program ratings. Rating methodology for security program maturity.
IEC 62443-2-3: Patch management in the IACS environment. Critical for OT environments.
IEC 62443-2-4: Service provider security program. Required for system integrators + service providers.
IEC 62443-3-1: Security technologies for IACS. Technical security controls.
IEC 62443-3-2: Security risk assessment for system design. Zone + conduit + SL determination.
IEC 62443-3-3: System security requirements and security levels. Core system-level standard.
IEC 62443-4-1: Product development requirements. Required for IACS component manufacturers.
IEC 62443-4-2: Component security technical requirements. Critical for component certification.
Geographic adoption: Adopted as EN 62443 (EU), UL 8660 series (US), GB/T 33007 (China). ISA-99 origin (US). Converted to IEC.
B2B relevance: For B2B protective cases containing industrial control equipment (PLCs, SCADA, DCS, RTUs, sensors, actuators), IEC 62443 SL 1-4 + zone & conduit + cybersecurity controls is procurement requirement for Industry 4.0 + critical infrastructure.
Security Levels (SL) 1-4 + Zone & Conduit Model
IEC 62443 defines Security Levels SL 1 (casual) to SL 4 (state-sponsored). Zone + conduit model is core design pattern.
Security Level (SL): Per IEC 62443-3-3. Discrete level 1-4 corresponding to threat actor capability + motivation + resources.
SL 1 (Casual / Coincidental): Protection against casual / coincidental violation. Low motivation + general IT skills. Examples: unauthorized access by internal employee.
SL 2 (Intentional / Simple): Protection against intentional violation with simple means + low resources + generic skills. Examples: disgruntled employee, hacktivist.
SL 3 (Intentional / Sophisticated): Protection against intentional violation with sophisticated means + moderate resources + IACS-specific skills. Examples: organized crime, ransomware operator.
SL 4 (Intentional / Sophisticated / Coordinated): Protection against intentional violation with sophisticated means + extensive resources + IACS-specific skills. Examples: nation-state APT, state-sponsored.
SL Target (SL-T): Desired security level per zone. SL Capability (SL-C): Capability of security control to resist SL-T. SL-Achieved (SL-A): Actual achieved SL after deployment.
Zone: Per IEC 62443-3-3 + 62443-3-2. Logical grouping of physical and logical assets sharing common security requirements.
Conduit: Logical grouping of communication channels between zones. Logical access control + monitoring required.
Zone & conduit model: Core design pattern. Each zone has defined SL-T. Conducts implement boundary controls (firewall + IDS + DMZ + access control).
Examples: Safety zone (SL-3), Control zone (SL-2), Operations zone (SL-2), DMZ (SL-3), Business zone (SL-1) typically.
Common reference model: Purdue / ISA-95 model + IEC 62443 zones alignment. Levels 0-1 (process + control), Level 2 (control), Level 3 (operations), Levels 4-5 (business + enterprise).
SL-T determination: Per IEC 62443-3-2 risk assessment. Based on worst-case consequence (safety, financial, operational, environmental, regulatory).
B2B recommendation: For industrial cybersecurity cases, identify zones + SL-T per zone + conduit controls + IEC 62443-3-3 SL-3 typically for critical infrastructure.
System Requirements (62443-3-3) + Foundational Requirements
IEC 62443-3-3 defines 7 Foundational Requirements (FR) + System Requirements (SR) for each FR. Core compliance standard for system integrators.
IEC 62443-3-3: "System security requirements and security levels". Core system-level standard. Defines Foundational Requirements (FR) + System Requirements (SR).
FR 1 (Identification and authentication control): Identify + authenticate all human users + software processes + devices. SR 1.1 (Identification), SR 1.2 (Authentication), SR 1.3 (Account management), SR 1.4 (Identifier management), SR 1.5 (Authenticator management), SR 1.6 (Wireless access mgmt), SR 1.7 (Strength of password), SR 1.8 (Public key infrastructure), SR 1.9 (Strength of public key auth), SR 1.10 (Authenticator feedback), SR 1.11 (Unsuccessful login), SR 1.12 (System use notification), SR 1.13 (Access via untrusted networks), SR 1.14 (Strength of identified user).
FR 2 (Use control): Enforce assigned authorizations. SR 2.1 (Authorization enforcement), SR 2.2 (Wireless use control), SR 2.3 (Use control for portable devices), SR 2.4 (Mobile code), SR 2.5 (Session lock), SR 2.6 (Remote session termination), SR 2.7 (Concurrent session control), SR 2.8 (Auditable events), SR 2.9 (Storage of audit info), SR 2.10 (Audit reduction + report generation), SR 2.11 (Time stamps), SR 2.12 (Audit review), SR 2.13 (Programmable audit).
FR 3 (System integrity): Ensure integrity of system + data. SR 3.1 (Communication integrity), SR 3.2 (Malicious code protection), SR 3.3 (Security functionality verification), SR 3.4 (Software + info integrity), SR 3.5 (Input validation), SR 3.6 (Deterministic output), SR 3.7 (Error handling), SR 3.8 (Session integrity), SR 3.9 (Audit information availability).
FR 4 (Data confidentiality): Ensure confidentiality of data at rest + in transit. SR 4.1 (Information confidentiality), SR 4.2 (Information persistence), SR 4.3 (Use of cryptography).
FR 5 (Restricted data flow): Restrict + segment data flow per zone & conduit model. SR 5.1 (Network segmentation), SR 5.2 (Zone boundary protection), SR 5.3 (General purpose person-to-person communication restrictions), SR 5.4 (Application partitioning).
FR 6 (Timely response to events): Respond to security events. SR 6.1 (Audit log accessibility), SR 6.2 (Continuous monitoring).
FR 7 (Resource availability): Ensure availability of system + data. SR 7.1 (Resource management / flooding), SR 7.2 (Resource management / limits), SR 7.3 (System backup), SR 7.4 (System recovery + reconstruction), SR 7.5 (Emergency power), SR 7.6 (Network bandwidth), SR 7.7 (Control system backup).
System Requirements (SR) per IEC 62443-3-3: 51 SR total across 7 FR. Each SR has SL-1, SL-2, SL-3, SL-4 requirements. Higher SL = stricter requirements.
Common SL-3 baseline: SR 1.1, 1.2, 1.3, 1.7, 1.13, 2.1, 2.4, 2.5, 2.8, 3.1, 3.4, 3.7, 4.1, 4.3, 5.1, 5.2, 6.1, 6.2, 7.1, 7.3, 7.4 - typical.
B2B recommendation: For industrial cases containing control equipment, require IEC 62443-3-3 SL-2 baseline + SL-3 for critical infrastructure, with documentation of all 51 SR per SL.
Component Requirements (62443-4-1 + 4-2) + Certification
IEC 62443-4-1 (process) + 62443-4-2 (component technical). Required for IACS component manufacturers + ISASecure + EDSA + Achilles certifications.
IEC 62443-4-1: "Product development requirements". Secure Development Lifecycle (SDL) for IACS components. Replaces ISA-99 + IEC 62443-4-1:2013.
SDL practices: (1) Security management (governance + accountability). (2) Security requirements + design. (3) Secure implementation (coding standards + static analysis). (4) Verification + validation (security testing). (5) Defect management. (6) Patch management. (7) Security documentation + end-of-life.
IEC 62443-4-2: "Component security technical requirements". Technical security requirements for IACS components. CR (Component Requirements) per FR.
CR per FR: 7 FR + CR for each component type. SFC (Security Function Capability) for SL-1, SL-2, SL-3, SL-4.
IEC 62443-4-2 vs IEC 62443-3-3: 3-3 is system-level (system integrator scope). 4-2 is component-level (component manufacturer scope). Both required.
Component certification: ISASecure EDSA (Embedded Device Security Assurance) certification. ISASecure CSA (Component Security Assurance). ISASecure SDLA (Security Development Lifecycle Assurance).
ISASecure EDSA certifies component per IEC 62443-4-2 (component requirements) + IEC 62443-4-1 (process) + ISASecure certification framework.
Achilles certification: Per ISA Security Compliance Institute (ISCI) Achilles platform. Communications robustness testing for IACS components.
IECEE CB Scheme: IEC 62443 now part of IECEE CB Scheme. CB test certificate accepted in 50+ countries for IEC 62443-4-2 component certification.
Test lab: TUV SUD / TUV NORD / TUV Rheinland / DNV / LRQA / BSI / SGS / Intertek / DEKRA. All accredited for IEC 62443 component certification.
Cost: IEC 62443-4-2 component certification EUR 30,000-100,000 per component. Process audit (4-1) EUR 30,000-80,000. Surveillance EUR 15,000-50,000 per year.
B2B recommendation: For industrial cases containing IACS components (PLCs, RTUs, sensors, actuators), require IEC 62443-4-1 + 4-2 component certification + ISASecure EDSA for SL-2+ or as required by zone SL-T.
OT / IT Integration + NIS 2 + ISO 27001
IEC 62443 integrates OT + IT cybersecurity. NIS 2 (EU) mandates OT cybersecurity. ISO 27001 covers IT. Combined framework.
OT (Operational Technology): Hardware + software + networks operating industrial processes. EYES: ICS / SCADA / DCS / RTU / PLC / HMI / IED.
OT vs IT cybersecurity: Different priorities. OT prioritizes availability + safety + integrity. IT prioritizes confidentiality. OT systems typically run 24/7 with limited maintenance windows.
OT security challenges: Legacy systems (Windows XP, Windows Server 2003), proprietary protocols (Modbus, DNP3, Profinet, EtherNet/IP), air-gapped myth (rarely true air-gap), limited patch management, long lifecycle (15-30 years), safety implications.
IEC 62443 + IT frameworks: IEC 62443 for OT + ISO 27001 for IT + NIST CSF for general + NIS 2 for EU critical infrastructure.
NIS 2 Directive (EU 2022/2555): EU-wide cybersecurity directive. Transposed by Member States October 2024. Covers essential + important entities. Essential entities must implement OT cybersecurity per IEC 62443.
NIS 2 entity categories: Essential (energy + transport + banking + health + water + digital infrastructure + public administration + space) + Important (manufacturing + food + waste + postal + chemical + research).
NIS 2 requirements: (1) Risk assessment + policies. (2) Incident handling. (3) Business continuity + crisis management. (4) Supply chain security. (5) Vulnerability handling + disclosure. (6) Encryption + cryptography. (7) Access control + asset management. (8) Effectiveness assessment.
NIS 2 fines: Essential entities up to EUR 10M or 2% global annual turnover. Important entities up to EUR 7M or 1.4% global annual turnover. Management liability.
ISO 27001:2022: IT cybersecurity ISMS. 93 Annex A controls. ISO 27001 + IEC 62443 combined: ISO 27001 for ISMS + IEC 62443 for OT technical controls.
NIST CSF 2.0 (2024): Framework for Improving Critical Infrastructure Cybersecurity. Five functions: Identify + Protect + Detect + Respond + Recover. Aligns with IEC 62443 + ISO 27001.
Common OT attack vectors: Phishing (plant engineer), removable media (USB), remote access (vendor support), supply chain (compromised component), insider threat, ransomware.
IEC 62443 vs NIST CSF: IEC 62443 is IACS-specific (OT-centric). NIST CSF is general (IT + OT + IoT). Many organizations use NIST CSF for program + IEC 62443 for IACS-specific controls.
B2B procurement workflow: (1) Identify zone + SL-T per IEC 62443-3-2. (2) Verify IACS component at IEC 62443-4-1 + 4-2 + ISASecure EDSA. (3) Verify system integrator at IEC 62443-2-4 service provider. (4) Verify asset owner ISMS per ISO 27001 + IEC 62443-2-1. (5) NIS 2 compliance if EU essential / important entity. (7) Supply chain cybersecurity per ISO 27001 + IEC 62443-2-4.
B2B recommendation: For industrial cases, require IEC 62443-3-3 SL-2 baseline + 4-1 + 4-2 component cert + ISO 27001 for ISMS + NIS 2 compliance for EU essential / important entities + supply chain cybersecurity assessment.
重要なポイント
- IEC 62443 is global IACS cybersecurity standard. Series covers general + policies + system + component. Required by NIS 2 (EU 2022/2555) for EU essential + important entities.
- Security Levels (SL) 1-4: SL 1 (casual) to SL 4 (state-sponsored APT). SL-T (target) + SL-C (capability) + SL-A (achieved) per zone.
- Zone and conduit model: zone = logical grouping of assets with common SL-T. Conduit = communication channel with boundary controls.
- IEC 62443-3-3: 7 Foundational Requirements + 51 System Requirements per SL. IEC 62443-4-1 + 4-2: component-level certification. ISASecure EDSA certifies components.
- IEC 62443 + ISO 27001 + NIS 2 combined framework: IEC 62443 for OT technical controls. ISO 27001 for ISMS. NIS 2 for EU essential/important entities.
- B2B recommendation: For industrial cases, require IEC 62443-3-3 SL-2 baseline + 4-1 + 4-2 component cert + tamper-evident design + hardware security module + Faraday cage + EMC shielding.
よくある質問
q
a
q
a
q
a
q
a
q
a