ISA updates ISA/IEC 62443 cybersecurity standard


Thursday, 30 January, 2025

ISA updates ISA/IEC 62443 cybersecurity standard

The International Society of Automation (ISA) has announced the publication of ANSI/ISA-62443-2-1-2024, Security for Industrial Automation and Control Systems, the latest update to the ISA/IEC 62443 series of standards.

Addressing cybersecurity on an organisation-wide basis can be a daunting challenge for companies that rely on industrial automation and control systems (IACS) in their manufacturing, processing and critical infrastructure operations. The ISA says that while no one-size-fits-all set of security practices can meet the widely varying security needs across global industry, ANSI/ISA-62443-2-1-2024 addresses the complexity by setting forth requirements for establishing, implementing, maintaining and continually improving a security program intended to reduce IACS security risks to tolerable levels. The requirements are written to be implementation independent, allowing asset owners to select approaches most suitable to their needs.

The standards are developed by the ISA99 Standards Committee as American National Standards, with simultaneous review and adoption by the Geneva-based International Electrotechnical Commission. ISA99 draws on the input of cybersecurity experts across the globe in developing the standards, which are applicable to all industry sectors and critical infrastructure in providing a flexible and comprehensive framework to address and mitigate current and future security vulnerabilities in IACS.

“Security is a balance of risk versus cost, and each situation will be different,” said ISA99 Co-Chair Eric Cosman of OIT Concepts. “In some, the risk can be related to health, safety and environmental factors rather than purely economic impact — presenting the possibility of an unrecoverable consequence instead of a temporary financial setback. Thus, a predetermined set of mandatory security practices could be overly restrictive and costly — or else insufficient to address the risk. This newly updated standard provides the flexibility to reach the right level of risk versus cost for a given operation.”

To learn more about the ISA/IEC 62443 series of standards, visit www.isa.org/62443standards.

Image credit: iStock.com/AEKKARAT DOUNGMANEERATTANA

Related News

OFS launches AI‍-‍based productivity solution for manufacturing

Australian-built generative AI software includes real‍-‍time insights facilitating a...

Australia the fourth most popular target for industrial cyber attacks: report

Report finds wireless networks found to be unprotected as threats to critical...

Manufacturing now a primary target for cyber attacks: report

Dragos reports that OT‍/‍ICS cyberthreats are escalating amid geopolitical conflicts and...


  • All content Copyright © 2025 Westwick-Farrow Pty Ltd