{"id":3308,"date":"2022-03-21T14:18:04","date_gmt":"2022-03-21T14:18:04","guid":{"rendered":"https:\/\/itegriti.com\/staging\/?p=3308"},"modified":"2022-03-22T18:11:34","modified_gmt":"2022-03-22T18:11:34","slug":"what-is-isa-iec-62443","status":"publish","type":"post","link":"https:\/\/itegriti.com\/staging\/2022\/managed-services\/what-is-isa-iec-62443\/","title":{"rendered":"What Is ISA\/IEC 62443?"},"content":{"rendered":"<p>[fusion_builder_container hundred_percent=&#8221;no&#8221; hundred_percent_height=&#8221;no&#8221; hundred_percent_height_scroll=&#8221;no&#8221; hundred_percent_height_center_content=&#8221;yes&#8221; equal_height_columns=&#8221;no&#8221; hide_on_mobile=&#8221;small-visibility,medium-visibility,large-visibility&#8221; status=&#8221;published&#8221; background_position=&#8221;center center&#8221; background_repeat=&#8221;no-repeat&#8221; fade=&#8221;no&#8221; background_parallax=&#8221;none&#8221; enable_mobile=&#8221;no&#8221; parallax_speed=&#8221;0.3&#8243; video_aspect_ratio=&#8221;16:9&#8243; video_loop=&#8221;yes&#8221; video_mute=&#8221;yes&#8221; border_style=&#8221;solid&#8221; type=&#8221;legacy&#8221; admin_toggled=&#8221;no&#8221;][fusion_builder_row][fusion_builder_column type=&#8221;1_1&#8243; layout=&#8221;1_1&#8243; spacing=&#8221;&#8221; center_content=&#8221;no&#8221; link=&#8221;&#8221; target=&#8221;_self&#8221; min_height=&#8221;&#8221; hide_on_mobile=&#8221;small-visibility,medium-visibility,large-visibility&#8221; class=&#8221;&#8221; id=&#8221;&#8221; background_color=&#8221;&#8221; background_image=&#8221;&#8221; background_image_id=&#8221;&#8221; background_position=&#8221;left top&#8221; background_repeat=&#8221;no-repeat&#8221; hover_type=&#8221;none&#8221; border_color=&#8221;&#8221; border_style=&#8221;solid&#8221; border_position=&#8221;all&#8221; border_radius=&#8221;&#8221; box_shadow=&#8221;no&#8221; dimension_box_shadow=&#8221;&#8221; box_shadow_blur=&#8221;0&#8243; box_shadow_spread=&#8221;0&#8243; box_shadow_color=&#8221;&#8221; box_shadow_style=&#8221;&#8221; padding_top=&#8221;&#8221; padding_right=&#8221;&#8221; padding_bottom=&#8221;&#8221; padding_left=&#8221;&#8221; margin_top=&#8221;&#8221; margin_bottom=&#8221;&#8221; animation_type=&#8221;&#8221; animation_direction=&#8221;left&#8221; animation_speed=&#8221;0.3&#8243; animation_offset=&#8221;&#8221; last=&#8221;true&#8221; border_sizes_top=&#8221;0&#8243; border_sizes_bottom=&#8221;0&#8243; border_sizes_left=&#8221;0&#8243; border_sizes_right=&#8221;0&#8243; first=&#8221;true&#8221;][fusion_text columns=&#8221;&#8221; column_min_width=&#8221;&#8221; column_spacing=&#8221;&#8221; rule_style=&#8221;default&#8221; rule_size=&#8221;&#8221; rule_color=&#8221;&#8221; content_alignment_medium=&#8221;&#8221; content_alignment_small=&#8221;&#8221; content_alignment=&#8221;&#8221; hide_on_mobile=&#8221;small-visibility,medium-visibility,large-visibility&#8221; sticky_display=&#8221;normal,sticky&#8221; class=&#8221;&#8221; id=&#8221;&#8221; margin_top=&#8221;&#8221; margin_right=&#8221;&#8221; margin_bottom=&#8221;&#8221; margin_left=&#8221;&#8221; font_size=&#8221;&#8221; fusion_font_family_text_font=&#8221;&#8221; fusion_font_variant_text_font=&#8221;&#8221; line_height=&#8221;&#8221; letter_spacing=&#8221;&#8221; text_color=&#8221;&#8221; animation_type=&#8221;&#8221; animation_direction=&#8221;left&#8221; animation_speed=&#8221;0.3&#8243; animation_offset=&#8221;&#8221;]<\/p>\n<p>Attacks and vulnerabilities involving industrial control systems (ICS) have been on the rise in recent years. For instance, <a href=\"https:\/\/usa.kaspersky.com\/about\/press-releases\/2021_kaspersky-finds-threats-against-ics-on-the-rise-in-h2-2020\" target=\"_blank\" rel=\"noopener\">Kaspersky<\/a> revealed that attacks targeting ICS systems had increased 62% over the second half of 2020. It was a similar story in H1 2021 when <a href=\"https:\/\/betanews.com\/2021\/08\/18\/ics-vulnerabilities-rise-attacks-increase\/\" target=\"_blank\" rel=\"noopener\">BetaNews<\/a> reported a 41% increase in the volume of ICS vulnerabilities. (ICS weaknesses grew just 25% between 2019 and 2020, by comparison.) Now with <a href=\"https:\/\/industrialcyber.co\/threats-attacks\/log4shell-vulnerability-may-have-affected-close-to-10-percent-of-ics-systems-globally\/\" target=\"_blank\" rel=\"noopener\">Industrial Cyber<\/a> noting in early 2022 how Log4Shell might have affected at least one-tenth of ICS systems globally, it doesn\u2019t appear that ICS threats will be slowing down anytime soon.<\/p>\n<p>These developments emphasize the need for organizations to protect their ICS and other Operational Technology (OT) assets. They can use ISA\/IEC 62443 towards that end. Let\u2019s explore how below.<\/p>\n<h2>Overview of ISA\/IEC 62443<\/h2>\n<p>ISA\/IEC 62443 is a set of standards that organizations can use to secure their industrial automation and control systems (IACS) throughout their lifecycles. The International Electrochemical Commission (IEC) and the International Society of Automation (ISA) initially developed ISA\/IEC 62443 for use in industrial processing sectors only. However, they recognize that IEC 62443 is applicable to power and energy distribution centers, among other entities, as organizations increasingly adopt IACS technologies\u2026and find that traditional IT security best practices can\u2019t protect those systems.<\/p>\n<p>\u201cIT standards are not appropriate for IACS and other OT (operational technology) environments,\u201d IEC explained in a <a href=\"https:\/\/www.iec.ch\/blog\/understanding-iec-62443\" target=\"_blank\" rel=\"noopener\">blog post<\/a>. \u201cFor example, they have different performance and availability requirements, and equipment lifetime. Moreover, cyber-attacks on IT systems have are essentially economic consequences, while cyber-attacks on critical infrastructure can also be heavily environmental or even threaten public-health and lives.\u201d<\/p>\n<p>Acknowledging this reality, IEC and ISA designed the standards to help organizations take a risk-based approach to secure their IACS. As such, ISA\/IEC 62443 doesn\u2019t just apply to the IACS technology itself. It also pertains to countermeasures and employee awareness. If properly addressed, these supporting elements can help to prevent a security incident from occurring in the first place, minimize the effects of an incident when it does occur, and augment security throughout the entire lifecycle.<\/p>\n<p>ISA\/IEC 62443 consists of four parts:<\/p>\n<ul>\n<li>A <strong>General<\/strong> section that includes terminology and topics that are relevant to the standards.<\/li>\n<li>A portion dedicated to <strong>Policies and Procedures<\/strong> that organizations can use to bolster their IACS security. These practices include establishing a formal security program for their IACS assets and delineating security requirements for IACS service providers.<\/li>\n<li>An overview of IACS security technologies and other <strong>System<\/strong>-level requirements.<\/li>\n<li>A compendium of <strong>Components and Requirements<\/strong> that help to ensure a secure product development lifecycle for IACS systems.<\/li>\n<\/ul>\n<p>Some of ISA\/IEC 62443 has been around since the early 2000s. But that doesn\u2019t mean the series is outdated. On the contrary, the ISA99 committee of the International Society of Automation (ISA) and IEC Technical Committee 65 Working Group 10 develop the standards on an ongoing basis. Such refinement ultimately motivated IEC to <a href=\"https:\/\/www.isa.org\/intech-home\/2021\/december-2021\/departments\/isa-iec-62443-cybersecurity-series-designated-as-i\" target=\"_blank\" rel=\"noopener\">designate the series as \u201chorizontal\u201d in December 2021<\/a>, which means that the standards are now applicable to a variety of industries. This enables stakeholders who are operating in multiple sectors to use ISA\/IEC 62443 as \u201cthe one single source for the fundamental principles and requirements of automation cybersecurity.\u201d Similarly, automation system suppliers can now use the standards to certify their products for applications in a broader range of industries, all while the ISA Global Cybersecurity Alliance works with asset owners to help them to adopt the series in their organizations.<\/p>\n<h2>Overcoming the Challenges with Implementing ISA\/IEC 62443<\/h2>\n<p>Notwithstanding the benefits of the \u201chorizontal\u201d designation discussed above, many organizations struggle to implement ISA\/IEC 62443. That\u2019s especially the case when they\u2019re grappling with challenges involving their OT security efforts in general. In the 2021 <a href=\"https:\/\/itegriti.com\/staging\/2022\/managed-services\/applied-risk-report-hints-at-the-future-of-next-gen-ot\/\">survey<\/a>, for instance, two-thirds of OT and Information Technology (IT) security practitioners said that sophisticated attacks on par with the <a href=\"https:\/\/itegriti.com\/staging\/2021\/cybersecurity\/what-you-need-to-know-about-the-cyber-attack-against-colonial-pipeline\/\" target=\"_blank\" rel=\"noopener\">Colonial Pipeline incident<\/a> were making it more difficult for them to manage their organization\u2019s OT security. Slightly fewer (55%) said that the growing complexity of their organization\u2019s OT environments was hindering their ability to achieve comprehensive visibility into assets and potential threats. Others went on to indicate that the defensive capabilities deployed in those environments weren\u2019t fulfilling their organization\u2019s OT security requirements.<\/p>\n<p>Fortunately, the challenges aren\u2019t insurmountable. Teams can overcome them by ensuring that they have the necessary budget to meet their organization\u2019s security requirements. IT and OT decision-makers might consider specifically <a href=\"https:\/\/itegriti.com\/staging\/2021\/managed-services\/on-the-importance-of-investing-in-cybersecurity\/\" target=\"_blank\" rel=\"noopener\">gaining buy-in from stakeholders<\/a>, as they can use that support to develop business use cases that explain the need for the proposed cybersecurity enhancements. The operative word there is \u201cbusiness\u201d; decision-makers need to frame whatever security challenges and proposed solutions they wish to discuss in terms of the business.<\/p>\n<p>Once they have the necessary budget, decision-makers can maximize their resources by directing them to managed security services. Working with a managed security services provider (MSSP like ITEGRITI can help to provide organizations with continuous cybersecurity and compliance services like vCISO and Workforce Support. They can use those offerings to implement the ISA\/IEC 62443 and to keep up with new versions of the series as they emerge.<\/p>\n<p><a href=\"https:\/\/itegriti.com\/staging\/managed-services\/\">Learn how ITEGRITI can manage your implementation of ISA\/IEC 62443<\/a>.<\/p>\n<p>[\/fusion_text][\/fusion_builder_column][\/fusion_builder_row][\/fusion_builder_container]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[fusion_builder_container hundred_percent=&#8221;no&#8221; hundred_percent_height=&#8221;no&#8221; hundred_percent_height_scroll=&#8221;no&#8221; hundred_percent_height_center_content=&#8221;yes&#8221; equal_height_columns=&#8221;no&#8221; hide_on_mobile=&#8221;small-visibility,medium-visibility,large-visibility&#8221; status=&#8221;published&#8221; background_position=&#8221;center center&#8221; background_repeat=&#8221;no-repeat&#8221; fade=&#8221;no&#8221; background_parallax=&#8221;none&#8221; enable_mobile=&#8221;no&#8221; parallax_speed=&#8221;0.3&#8243; video_aspect_ratio=&#8221;16:9&#8243; video_loop=&#8221;yes&#8221; video_mute=&#8221;yes&#8221; border_style=&#8221;solid&#8221; type=&#8221;legacy&#8221; admin_toggled=&#8221;no&#8221;][fusion_builder_row][fusion_builder_column type=&#8221;1_1&#8243; layout=&#8221;1_1&#8243; spacing=&#8221;&#8221; center_content=&#8221;no&#8221; link=&#8221;&#8221; target=&#8221;_self&#8221; min_height=&#8221;&#8221; hide_on_mobile=&#8221;small-visibility,medium-visibility,large-visibility&#8221; class=&#8221;&#8221; id=&#8221;&#8221; background_color=&#8221;&#8221; background_image=&#8221;&#8221; background_image_id=&#8221;&#8221; background_position=&#8221;left top&#8221; background_repeat=&#8221;no-repeat&#8221; hover_type=&#8221;none&#8221; border_color=&#8221;&#8221; border_style=&#8221;solid&#8221; border_position=&#8221;all&#8221; border_radius=&#8221;&#8221; box_shadow=&#8221;no&#8221; dimension_box_shadow=&#8221;&#8221; box_shadow_blur=&#8221;0&#8243; box_shadow_spread=&#8221;0&#8243; box_shadow_color=&#8221;&#8221; box_shadow_style=&#8221;&#8221; padding_top=&#8221;&#8221; padding_right=&#8221;&#8221; [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":3312,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2180],"tags":[],"_links":{"self":[{"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/posts\/3308"}],"collection":[{"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/comments?post=3308"}],"version-history":[{"count":3,"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/posts\/3308\/revisions"}],"predecessor-version":[{"id":3311,"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/posts\/3308\/revisions\/3311"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/media\/3312"}],"wp:attachment":[{"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/media?parent=3308"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/categories?post=3308"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itegriti.com\/staging\/wp-json\/wp\/v2\/tags?post=3308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}