What is IEC 62443-1-1?

IEC 62443-1-1 is the foundation of the IEC 62443 series: the part that defines the terminology, concepts and models for securing industrial automation and control systems (IACS). It was published in 2009 as a technical specification (IEC TS 62443-1-1) and builds on the work of the ISA99 committee. To understand the other parts of the standard, such as IEC 62443-3-3 or IEC 62443-4-2, you need the concepts from 1-1.


🧠 Which core concepts does IEC 62443-1-1 introduce?

  • IACS — the combination of people, hardware, software and procedures that controls an industrial process, not just the technology
  • Zones and conduits — groups of assets with the same security requirements, and the controlled communication paths between them (zones and conduits model)
  • Security levels — the degree of protection, from SL 1 (casual misuse) to SL 4 (an attacker with extensive resources)
  • Defense in Depth — multiple layers of defence instead of a single barrier
  • Reference models — including a level model based on the Purdue Model, from field devices up to business systems
  • Roles — asset owner, product supplier and service provider or integrator

🔧 What are the seven foundational requirements?

FR Name Purpose
FR 1 Identification and authentication control (IAC) Knowing who or what is requesting access (authentication)
FR 2 Use control (UC) Determining what a user may do (least privilege)
FR 3 System integrity (SI) Preventing unauthorised changes
FR 4 Data confidentiality (DC) Protecting sensitive information
FR 5 Restricted data flow (RDF) Limiting data flows through segmentation
FR 6 Timely response to events (TRE) Detecting and responding to incidents
FR 7 Resource availability (RA) Availability even during an attack

These seven FRs structure the system requirements in 3-3 and the component requirements in 4-2. They also show how OT differs from IT: in an industrial environment, availability and integrity often outweigh confidentiality.


🗂️ How is the IEC 62443 series structured?

Group Audience Examples
1 – General Everyone 1-1 concepts and models
2 – Policies and procedures Asset owner, service providers IEC 62443-2-1 (security programme), IEC 62443-2-4 (service providers)
3 – System Integrator, asset owner IEC 62443-3-2 (risk assessment), IEC 62443-3-3 (system requirements)
4 – Component Product supplier IEC 62443-4-1 (development process), IEC 62443-4-2 (component requirements)

🔄 What is the difference between IEC 62443-1-1 and ISA-99?

ISA-99 was the name of the American ISA committee and of the first standards for industrial cybersecurity. The work was later continued together with the IEC as the international IEC 62443 series; ISA publishes the same documents as ISA-62443. Part 1-1 derives directly from the first ISA-99 document on concepts and models.


🛠️ How do you apply the concepts from 1-1 in practice?

A typical first approach at an asset owner follows the concepts from 1-1 in this order:

  1. Define the system boundary — which installations, networks and people are part of the IACS?
  2. Inventory assets — which controllers, servers, network components and software are there (Asset Inventory)?
  3. Form zones — group assets with the same function and the same risk, for example safety, production line 1 control, engineering
  4. Define conduits — which communication between zones is needed, and via which path?
  5. Determine security levels — what level does each zone need (continued in IEC 62443-3-2)?
  6. Define roles — what does the organisation do itself, what does the integrator do and what does the product supplier do?
Role Key parts of IEC 62443
Asset owner 2-1, 3-2, 3-3
Integrator / service provider 2-4, 3-2, 3-3
Product supplier 4-1, 4-2

❓ Frequently asked questions

What does IEC 62443-1-1 contain?

IEC 62443-1-1 contains the terminology, concepts and models of the IEC 62443 series. Among other things it describes what an IACS is, the zones and conduits model, the security levels, the seven foundational requirements, the principle of defence in depth and a reference model based on the Purdue model.

What are the seven foundational requirements of IEC 62443?

The seven foundational requirements of IEC 62443 are: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events and resource availability. All technical requirements in IEC 62443-3-3 and IEC 62443-4-2 are organised under these seven.

What is a zone in IEC 62443?

A zone in IEC 62443 is a group of logical or physical assets with the same security requirements. Communication between zones runs through conduits, controlled connections with security measures such as firewalls. By forming zones, an organisation can apply the appropriate security level to each group of assets.

Is IEC 62443-1-1 still current?

IEC 62443-1-1 was published in 2009 as a technical specification, making it the oldest part of the series. Its core concepts, such as zones, conduits and security levels, are still used and have been elaborated further in later parts such as 3-2 and 3-3. For current practice, those later parts take precedence.

What is the difference between IEC 62443 and ISO 27001?

ISO 27001 is a standard for information security across the whole organisation, with an emphasis on the confidentiality of information. IEC 62443 focuses specifically on industrial automation and control systems, where availability and safety come first, and sets requirements for asset owners, integrators and product suppliers alike. Many organisations combine both standards.


📌 In summary

IEC 62443-1-1 establishes the common language of the IEC 62443 series: IACS, zones and conduits, security levels, roles and the seven foundational requirements. It is not a checklist but the reference framework on which all requirements in the other parts are built.