Framework overlap

Does OWASP ASVS cover IEC 62443?

You hold OWASP ASVS and have been told to do IEC 62443. Here is how much overlaps, control by control.

21% of IEC 62443 you already have

OWASP ASVS already covers about 21% of IEC 62443, leaving 64 of 81 controls as genuinely new work.

Already covered 0 Likely covered 17 New work 64

No control in OWASP ASVS maps directly to one in IEC 62443. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in OWASP ASVS reaches these. This is the list to scope.

62443-2-1-AC
Account Management and Access Control for IACS
62443-2-1-BCP
Business Continuity and Disaster Recovery for IACS
62443-2-1-CSMS
Cyber Security Management System (CSMS) for IACS
62443-2-1-IR
Incident Planning and Response for IACS
62443-2-1-MOC
Management of Change for IACS Security
62443-2-1-NSEG
Network Segmentation and Zone/Conduit Implementation
62443-2-1-PHY
Physical and Environmental Security of IACS Assets
62443-2-1-PM
Patch Management and System Update for IACS
62443-2-1-RA
IACS Risk Identification, Classification and Assessment
62443-2-1-TRN
Personnel Security Awareness and Training for IACS
62443-2-4-SP-01
Service Provider Security Program
62443-2-4-SP-02
Service Provider Solution Staffing and Assurance
62443-2-4-SP-03
Service Provider Architecture and Design Practices
62443-2-4-SP-04
Service Provider Wireless and Remote Access Practices
62443-2-4-SP-05
Service Provider Malware Protection Practices
62443-2-4-SP-06
Service Provider Backup and Restore Practices
62443-3-2-CRS
Document Cybersecurity Requirements Specification (CRS)
62443-3-2-ZCR-1
Identify System Under Consideration
62443-3-2-ZCR-2
High-Level Risk Assessment
62443-3-2-ZCR-3
Partition the SUC into Zones and Conduits
62443-3-2-ZCR-4
Detailed Cybersecurity Risk Assessment per Zone and Conduit
62443-3-3-FR1-SR-1-1
Human User Identification and Authentication (FR1)
62443-3-3-FR1-SR-1-11
Unsuccessful Login Attempts
62443-3-3-FR1-SR-1-2
Software Process and Device Identification and Authentication
62443-3-3-FR1-SR-1-5
Authenticator Management
62443-3-3-FR1-SR-1-7
Strength of Password-Based Authentication
62443-3-3-FR2-SR-2-1
Authorisation Enforcement (FR2 Use Control)
62443-3-3-FR2-SR-2-4
Mobile Code Restriction
62443-3-3-FR2-SR-2-5
Session Lock and Termination
62443-3-3-FR2-SR-2-8
Auditable Events
62443-3-3-FR3-SR-3-1
Communication Integrity (FR3 System Integrity)
62443-3-3-FR3-SR-3-2
Protection from Malicious Code
62443-3-3-FR3-SR-3-3
Security Functionality Verification
62443-3-3-FR3-SR-3-4
Software and Information Integrity
62443-3-3-FR3-SR-3-8
Session Integrity
62443-3-3-FR4-SR-4-1
Information Confidentiality (FR4 Data Confidentiality)
62443-3-3-FR4-SR-4-2
Information Persistence and Sanitisation
62443-3-3-FR5-SR-5-1
Network Segmentation (FR5 Restricted Data Flow)
62443-3-3-FR5-SR-5-2
Zone Boundary Protection
62443-3-3-FR5-SR-5-3
General-Purpose Person-to-Person Communication Restrictions
62443-3-3-FR6-SR-6-1
Audit Log Accessibility (FR6 Timely Response to Events)
62443-3-3-FR6-SR-6-2
Continuous Monitoring
62443-3-3-FR7-SR-7-1
Denial-of-Service Protection (FR7 Resource Availability)
62443-3-3-FR7-SR-7-3
Control System Backup
62443-3-3-FR7-SR-7-6
Network and Security Configurations
62443-4-1-DM
Defect Management and Vulnerability Handling
62443-4-1-SD
Secure by Design
62443-4-1-SG
Security Guidelines for Asset Owner
62443-4-1-SI
Secure Implementation
62443-4-1-SM
Security Management (Product Development)
62443-4-1-SR
Specification of Security Requirements
62443-4-1-SUM
Security Update Management
62443-4-1-SVV
Security Verification and Validation
62443-4-2-CR-1-1
Component Identification and Authentication of Users
62443-4-2-CR-3-1
Component Communication Integrity
62443-4-2-CR-7-1
Component Denial-of-Service Protection
62443-4-2-EDR-3-10
Embedded Device Support for Updates
IEC62443-01
Critical asset identification and inventory
IEC62443-03
Security governance structure
IEC62443-04
Roles and responsibilities for critical systems
IEC62443-06
Physical and logical access controls
IEC62443-09
Interactive remote access security
IEC62443-15
Ports and services management
IEC62443-19
Coordination with sector-specific agencies
Show the 17 you already have
IEC62443-02
System security categorization
IEC62443-05
Security policy for operational technology
IEC62443-07
Personnel risk assessment
IEC62443-08
Electronic access perimeter management
IEC62443-10
Revocation of access procedures
IEC62443-11
Security patch management for OT
IEC62443-12
Malware prevention for operational systems
IEC62443-13
Network security monitoring
IEC62443-14
System security hardening
IEC62443-16
Incident response plan for operational disruptions
IEC62443-17
Recovery plan for critical systems
IEC62443-18
Reporting obligations to authorities
IEC62443-20
Exercises and drills for OT incidents
IEC62443-21
Supply chain risk management for critical components
IEC62443-22
Configuration management for OT systems
IEC62443-23
Change management procedures
IEC62443-24
Vulnerability assessment for critical systems

How this is calculated

Already covered means a mapping runs from a control in OWASP ASVS to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition