Course Description
IEC 62443 is the international standard for industrial automation and control system security — the framework that asset owners, system integrators and product suppliers are increasingly required to demonstrate against in contracts, audits and regulation. It is the foundation on which sector-specific frameworks, including railway TS 50701, are built.
This course develops a working understanding of the IEC 62443 series and how to apply it. Participants learn the structure of the standard and the roles it defines, zones and conduits, security levels, the foundational requirements, risk assessment to 62443-3-2, security programme requirements for asset owners, and the system and component requirements that govern procurement — equipping industrial organisations to build and demonstrate a compliant security programme.
What you will achieve
By the end of this training course, participants will be able to:
- Explain the purpose and structure of the IEC 62443 series
- Understand the roles: asset owner, integrator, product supplier
- Apply zones and conduits to industrial systems
- Understand security levels (SL-T, SL-A, SL-C)
- Apply the seven foundational requirements
- Conduct risk assessment in line with 62443-3-2
- Understand security programme requirements (62443-2-1)
- Apply system and component requirements in procurement
How the course is delivered
The course works systematically through the IEC 62443 series with practical zoning, risk assessment and requirement-application exercises. Participants apply the standard to realistic industrial systems from process and power environments.
The programme is aimed at engineers and asset owners building a defensible security programme, not at penetration testers.
Designed for
This training course is ideal for:
- Automation, control and OT engineers
- Industrial cybersecurity professionals
- System integrators and product suppliers
- Plant and operations managers
- Anyone required to demonstrate IEC 62443 compliance
Daily programme
- Why industrial security is different from IT
- Structure of the 62443 series
- Roles: asset owner, integrator, product supplier
- Key concepts and terminology
- System under consideration
- Partitioning into zones and conduits
- Security levels: target, achieved, capability
- The seven foundational requirements
- Initial risk assessment
- Detailed risk assessment
- Threat and vulnerability analysis
- Documenting the risk assessment
- Security programme requirements for asset owners
- Policies, procedures and governance
- Patch and vulnerability management
- Service provider requirements
- System security requirements (62443-3-3)
- Component requirements (62443-4-2)
- Secure development lifecycle (62443-4-1)
- Procurement, compliance and workshop
Certification & accreditation
BII Certificate of Completion
BII Certificate of Completion Upon successful completion, participants receive a BII Development Institute Certificate of Completion with a unique reference code that is independently verifiable. Our certificates are recognised internationally and reflect successful completion of your chosen programme.