Skip to main content

IEC 62443 in the plant, not in a binder

Zones and conduits derived from the communication that actually runs. With a target security level per zone and an order of work that fits maintenance windows.

Zonen- und Conduit-Modell nach IEC 62443-3-2 Fuenf Ebenen, deren Uebergaenge einzeln bewertet sind: geprueft, lueckenhaft, oder gar nicht vorhanden. L4 OFFICE IT L3.5 DMZ L3 OPERATIONS L2 SCADA · HMI L1/0 PLC · FIELD IEC 62443 · ZONES AND CONDUITS
Trusted by
The starting position

A zone concept is a statement about the plant

A zone model can be drawn at a desk, but it only holds once it matches the connections that are actually open. The test of it is a single question: which paths run today between the office network and the control level, and are they all in the concept.

The standard is awkwardly concrete on this point. A zone model to 62443-3-2 is a statement about the architecture: which parts of the plant share a security level, where the boundary runs, and what may cross it. That cannot be written without knowing the plant.

So we start with the communication that really runs, and not with the network plan that ought to hold.

The core

Zones and transitions as they really run

Zonen- und Conduit-Modell nach IEC 62443-3-2 Fuenf Ebenen, deren Uebergaenge einzeln bewertet sind: geprueft, lueckenhaft, oder gar nicht vorhanden. L4 OFFICE IT L3.5 DMZ L3 OPERATIONS L2 SCADA · HMI L1/0 PLC · FIELD IEC 62443 · ZONES AND CONDUITS

Between office IT and the control level, many plants have a connection that grew there: a remote maintenance path nobody switched off, a historian with two network cards, an access granted to an integrator three years ago. On paper, level 3.5 is a line; in the plant it is a list of exceptions.

We record the actual communication, passively and during operation, and set it against the intended state. Out of that comes the zone and conduit model to 62443-3-2, with a target security level per zone and a list of the transitions that actually exist.

What regularly stands out is not the missing firewall but the path that goes around it.

The three parts that count

Which part of 62443 applies to whom

The series is extensive, but for an operator three parts decide it. The rest addresses manufacturers and integrators.

62443-2-1: the programme

What the operator has to build organisationally. Responsibilities, change and patch procedures, dealing with suppliers. The part that most resembles an ISMS and overlaps with NIS2.

62443-3-2: the zones

Risk analysis and the division of the plant into zones and conduits, each with a target security level. This is the part that means architecture and not only documentation.

62443-3-3: the requirements

What a system has to be capable of in order to reach a security level. This is where it shows whether a controller from 2009 can carry the target at all, or whether the compensation has to lie in the zone around it.

Approach

From the survey to the zone model

Four steps, with no intervention in the process.

1

Passive capture

Capture at the handover points, evaluation of the protocols that actually run: IEC 60870-5-104, IEC 61850 with MMS and GOOSE, Modbus, DNP3, OPC UA. No active scan in the production network.

2

Plant and communication picture

Which devices speak to which, in which direction, how often. Only from that does it become visible which boundaries already exist and which are merely asserted.

3

Zones and conduits

Division by protection requirement and function, a target security level per zone, and for every transition the question of what it has to carry and what it permits today.

4

Measures in order

Separated into immediate, next maintenance window, and capital planning. A plant cannot be rebuilt in a quarter, but it can be made safer in a sensible order.

Where this comes from

From plants, not from reading standards

Our zone models come out of the same work as our penetration tests and our OT monitoring: substations, control rooms, power plant environments and interlocking landscapes. What we find there in the way of transitions flows back into the question of which zone boundary holds in practice.

Our own research comes on top. Our lab holds real controllers, and in the demonstrators YekTrain, YekCar and YekCity we try attacks and detection on rigs that cost nobody their operation.

Common questions

Common questions about OT compliance

Products and processes get certified, not the plant as a whole. For operators the usual route is an evidenced programme to 62443-2-1 and a reasoned zone model to 3-2. We prepare both, but we do not audit what we have advised on.

NIS2 says you have to manage risks; 62443 says what that looks like in an automation environment. For operators of critical infrastructure, 62443 is the most workable way to evidence the state of the art.

No. The survey runs passively over mirror ports and captures. Active tests we do only on spare or lab rigs, or in agreed windows with abort criteria fixed beforehand.

That is the normal case and no reason to stop. If a device cannot carry a security level itself, the zone has to carry it. That is exactly what the model is for: it allows old technology to keep running and still lets you explain why that is defensible.

Credentials

Certifications and memberships.

Certifications held in the team
Memberships
eco – Verband der Internetwirtschaft
networker NRW
Next step

Talk to us.

A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Email
info@yekta-it.de
PGP key available
Location
Dortmund
Ruhrallee 9 · 44139