OT DEFENSEREVIEW

Intelligence for systems that move the physical world.

International voluntary standard · consensus industrial cybersecurity standard

ANSI/ISA-62443-3-2-2020 — Security risk assessment for system design

Part 3-2 addresses system-level risk assessment and the use of zones, conduits, and target security levels in IACS design.

What the authority record establishes

Part 3-2 addresses system-level risk assessment and the use of zones, conduits, and target security levels in IACS design.

Not law by itself

The exact official title, issuing body, jurisdiction, version or application record, and linked source define the scope of this page. Readers should not transfer the authority's status to a commercial product or infer transaction-, patient-, system-, site-, or organization-specific applicability from this summary.

Why it matters to this market

It provides the central architecture language for comparing discovery, segmentation modeling, enforcement, remote access, and controlled-transfer products.

Affected operating stages

  • System Definition
  • Risk Assessment
  • Zone And Conduit Design
  • Target Security Level
  • Documentation

Capabilities to examine

Topology, Communication, And Dependency Mapping

Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for topology, communication, and dependency mapping.

Asset Criticality And Operational Context

Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for asset criticality and operational context.

Network Segmentation Policy Modeling

Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for network segmentation policy modeling.

Industrial Firewall And Policy Enforcement

Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for industrial firewall and policy enforcement.

Unidirectional Transfer And Network Isolation

Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for unidirectional transfer and network isolation.

Secure Remote Access And Vendor Session Control

Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for secure remote access and vendor session control.

Compliance Mapping And Control Evidence

Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for compliance mapping and control evidence.

Affected buyer audiences

  • asset owners
  • system integrators
  • control engineers
  • security architects

Implementation questions

  • Which entities, products, populations, transactions, systems, sites, or jurisdictions are actually within scope?
  • What is binding, what is guidance, and what is a technical or consensus standard?
  • Which publication, adoption, effective, application, transition, and enforcement dates differ?
  • Who owns legal, clinical, quality, regulatory, policy, or operational interpretation?
  • How will a source revision affect open work and historical decisions?

Interpretation boundary

Tool-generated zones, scores, or diagrams do not replace accountable system definition, risk assessment, or engineering approval.