ANSI/ISA-62443-3-2-2020 — Security risk assessment for system design
Part 3-2 addresses system-level risk assessment and the use of zones, conduits, and target security levels in IACS design.
What the authority record establishes
Part 3-2 addresses system-level risk assessment and the use of zones, conduits, and target security levels in IACS design.
Not law by itself
The exact official title, issuing body, jurisdiction, version or application record, and linked source define the scope of this page. Readers should not transfer the authority's status to a commercial product or infer transaction-, patient-, system-, site-, or organization-specific applicability from this summary.
Why it matters to this market
It provides the central architecture language for comparing discovery, segmentation modeling, enforcement, remote access, and controlled-transfer products.
Affected operating stages
- System Definition
- Risk Assessment
- Zone And Conduit Design
- Target Security Level
- Documentation
Capabilities to examine
Topology, Communication, And Dependency Mapping
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for topology, communication, and dependency mapping.
Asset Criticality And Operational Context
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for asset criticality and operational context.
Network Segmentation Policy Modeling
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for network segmentation policy modeling.
Industrial Firewall And Policy Enforcement
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for industrial firewall and policy enforcement.
Unidirectional Transfer And Network Isolation
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for unidirectional transfer and network isolation.
Secure Remote Access And Vendor Session Control
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for secure remote access and vendor session control.
Compliance Mapping And Control Evidence
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for compliance mapping and control evidence.
Affected buyer audiences
- asset owners
- system integrators
- control engineers
- security architects
Implementation questions
- Which entities, products, populations, transactions, systems, sites, or jurisdictions are actually within scope?
- What is binding, what is guidance, and what is a technical or consensus standard?
- Which publication, adoption, effective, application, transition, and enforcement dates differ?
- Who owns legal, clinical, quality, regulatory, policy, or operational interpretation?
- How will a source revision affect open work and historical decisions?
Interpretation boundary
Tool-generated zones, scores, or diagrams do not replace accountable system definition, risk assessment, or engineering approval.