Skip to main content
Back

EVS-EN IEC 62443-2-1:2024

Security for industrial automation and control systems - Part 2-1: Security program requirements for IACS asset owners

General information

Valid from 01.10.2024
Base Documents
IEC 62443-2-1:2024; EN IEC 62443-2-1:2024
Directives or regulations
None

Standard history

Status
Date
Type
Name
01.10.2024
Main
IEC 62443-2-1:2024 specifies asset owner security program (SP) policy and procedure requirements for an industrial automation and control system (IACS) in operation. This document uses the broad definition and scope of what constitutes an IACS as described in IEC TS 62443‑1‑1. In the context of this document, asset owner also includes the operator of the IACS.
This document recognizes that the lifespan of an IACS can exceed twenty years, and that many legacy systems contain hardware and software that are no longer supported. Therefore, the SP for most legacy systems addresses only a subset of the requirements defined in this document. For example, if IACS or component software is no longer supported, security patching requirements cannot be met. Similarly, backup software for many older systems is not available for all components of the IACS. This document does not specify that an IACS has these technical requirements. This document states that the asset owner needs to have policies and procedures around these types of requirements. In the case where an asset owner has legacy systems that do not have the native technical capabilities, compensating security measures can be part of the policies and procedures specified in this document.
This edition includes the following significant technical changes with respect to the previous edition:
a) revised requirement structure into SP elements (SPEs),
b) revised requirements to eliminate duplication of an information security management system (ISMS), and
c) defined a maturity model for evaluating requirements.

Required fields are indicated with *

*
*
*
PDF
39.04 € incl tax
Paper
39.04 € incl tax
Browse standard from 2.44 € incl tax
Standard monitoring

Customers who bought this item also bought

Main

EVS-EN IEC 62443-2-4:2024

Security for industrial automation and control systems - Part 2-4: Security program requirements for IACS service providers
Newest version Valid from 01.02.2024
Main

EVS-EN IEC 62443-4-1:2018

Security for industrial automation and control systems - Part 4-1: Secure Product Development Lifecycle Requirements
Newest version Valid from 02.04.2018
Main

EVS-EN IEC 62443-4-2:2019

Security for industrial automation and control systems - Part 4-2: Technical security requirements for IACS components
Newest version Valid from 02.05.2019
Main

EVS-EN IEC 62443-3-2:2020

Security for industrial automation and control systems - Part 3-2: Security risk assessment for system design
Newest version Valid from 15.09.2020