22% of IEC 62443 you already have
ISO/SAE 21434 already covers about 22% of IEC 62443, leaving
63 of 81 controls as genuinely new work.
Already covered 9
Likely covered 9
New work 63
What is genuinely new work
Nothing in ISO/SAE 21434 reaches these. This is the list to scope.
62443-2-1-ACAccount Management and Access Control for IACS
62443-2-1-BCPBusiness Continuity and Disaster Recovery for IACS
62443-2-1-CSMSCyber Security Management System (CSMS) for IACS
62443-2-1-IRIncident Planning and Response for IACS
62443-2-1-MOCManagement of Change for IACS Security
62443-2-1-NSEGNetwork Segmentation and Zone/Conduit Implementation
62443-2-1-PHYPhysical and Environmental Security of IACS Assets
62443-2-1-PMPatch Management and System Update for IACS
62443-2-1-RAIACS Risk Identification, Classification and Assessment
62443-2-1-TRNPersonnel Security Awareness and Training for IACS
62443-2-4-SP-01Service Provider Security Program
62443-2-4-SP-02Service Provider Solution Staffing and Assurance
62443-2-4-SP-03Service Provider Architecture and Design Practices
62443-2-4-SP-04Service Provider Wireless and Remote Access Practices
62443-2-4-SP-05Service Provider Malware Protection Practices
62443-2-4-SP-06Service Provider Backup and Restore Practices
62443-3-2-CRSDocument Cybersecurity Requirements Specification (CRS)
62443-3-2-ZCR-1Identify System Under Consideration
62443-3-2-ZCR-2High-Level Risk Assessment
62443-3-2-ZCR-3Partition the SUC into Zones and Conduits
62443-3-2-ZCR-4Detailed Cybersecurity Risk Assessment per Zone and Conduit
62443-3-3-FR1-SR-1-1Human User Identification and Authentication (FR1)
62443-3-3-FR1-SR-1-11Unsuccessful Login Attempts
62443-3-3-FR1-SR-1-2Software Process and Device Identification and Authentication
62443-3-3-FR1-SR-1-5Authenticator Management
62443-3-3-FR1-SR-1-7Strength of Password-Based Authentication
62443-3-3-FR2-SR-2-1Authorisation Enforcement (FR2 Use Control)
62443-3-3-FR2-SR-2-4Mobile Code Restriction
62443-3-3-FR2-SR-2-5Session Lock and Termination
62443-3-3-FR2-SR-2-8Auditable Events
62443-3-3-FR3-SR-3-1Communication Integrity (FR3 System Integrity)
62443-3-3-FR3-SR-3-2Protection from Malicious Code
62443-3-3-FR3-SR-3-3Security Functionality Verification
62443-3-3-FR3-SR-3-4Software and Information Integrity
62443-3-3-FR3-SR-3-8Session Integrity
62443-3-3-FR4-SR-4-1Information Confidentiality (FR4 Data Confidentiality)
62443-3-3-FR4-SR-4-2Information Persistence and Sanitisation
62443-3-3-FR5-SR-5-1Network Segmentation (FR5 Restricted Data Flow)
62443-3-3-FR5-SR-5-2Zone Boundary Protection
62443-3-3-FR5-SR-5-3General-Purpose Person-to-Person Communication Restrictions
62443-3-3-FR6-SR-6-1Audit Log Accessibility (FR6 Timely Response to Events)
62443-3-3-FR6-SR-6-2Continuous Monitoring
62443-3-3-FR7-SR-7-1Denial-of-Service Protection (FR7 Resource Availability)
62443-3-3-FR7-SR-7-3Control System Backup
62443-3-3-FR7-SR-7-6Network and Security Configurations
62443-4-1-DMDefect Management and Vulnerability Handling
62443-4-1-SDSecure by Design
62443-4-1-SGSecurity Guidelines for Asset Owner
62443-4-1-SISecure Implementation
62443-4-1-SMSecurity Management (Product Development)
62443-4-1-SRSpecification of Security Requirements
62443-4-1-SUMSecurity Update Management
62443-4-1-SVVSecurity Verification and Validation
62443-4-2-CR-1-1Component Identification and Authentication of Users
62443-4-2-CR-3-1Component Communication Integrity
62443-4-2-CR-7-1Component Denial-of-Service Protection
62443-4-2-EDR-3-10Embedded Device Support for Updates
IEC62443-01Critical asset identification and inventory
IEC62443-03Security governance structure
IEC62443-06Physical and logical access controls
IEC62443-09Interactive remote access security
IEC62443-15Ports and services management
IEC62443-19Coordination with sector-specific agencies
Show the 18 you already have
IEC62443-02System security categorization
IEC62443-07Personnel risk assessment
IEC62443-08Electronic access perimeter management
IEC62443-10Revocation of access procedures
IEC62443-12Malware prevention for operational systems
IEC62443-13Network security monitoring
IEC62443-16Incident response plan for operational disruptions
IEC62443-17Recovery plan for critical systems
IEC62443-20Exercises and drills for OT incidents
IEC62443-04Roles and responsibilities for critical systems
IEC62443-05Security policy for operational technology
IEC62443-11Security patch management for OT
IEC62443-14System security hardening
IEC62443-18Reporting obligations to authorities
IEC62443-21Supply chain risk management for critical components
IEC62443-22Configuration management for OT systems
IEC62443-23Change management procedures
IEC62443-24Vulnerability assessment for critical systems
How this is calculated
Already covered means a mapping runs from a control in ISO/SAE 21434 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition