An asset owner operating a manufacturing plant wants guidance specifically on building an industrial cybersecurity management system (CSMS) for their organization. Within IEC 62443, which part most directly serves this need?
- A.IEC 62443-4-2, which lists technical requirements for individual components
- B.IEC 62443-3-3, which defines system security requirements and security levels
- C.IEC 62443-1-1, which provides terminology, concepts, and models
- D.IEC 62443-2-1, which establishes requirements for an IACS security management system
Why D is correct
IEC 62443-2-1 is written for asset owners and defines the elements of a cybersecurity management system covering policies, risk assessment, and operational practices. The 3-x and 4-x parts target technical system and component requirements rather than organizational program management.
Know someone studying for OT Security Fundamentals? Send them this one.