# IEC 62443-3-3: Industrial Automation and Control Systems Security

Framework id: `iec_62443`. Industrial Security. Publisher: ISA/IEC. Version: 2013. Region: Global. Mapping licence: CC BY-SA 4.0.
Source text: https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (29, average coverage 81%)
- 2-1 4.2 Security management system: PM-01, PM-02, PM-03, PM-09, PL-09 (68%)
- 2-1 4.3 Security risk assessment: RA-01, RA-02, RA-03, RA-05, RA-07, RA-09 (75%)
- 2-1 4.4 Addressing risk with the security management system: PM-09, CA-05, RA-03, RA-07 (68%)
- 3-3 SR 1.1 Human user identification and authentication: IA-02, IA-05, IA-08 (85%)
- 3-3 SR 1.2 Software process and device identification and authentication: IA-03, IA-09 (75%)
- 3-3 SR 1.3 Account management: AC-02, AC-05, AC-06 (90%)
- 3-3 SR 1.5 Authenticator management: IA-05 (85%)
- 3-3 SR 1.7 Strength of password-based authentication: IA-05 (90%)
- 3-3 SR 1.13 Access via untrusted networks: AC-17 (75%)
- 3-3 SR 2.1 Authorization enforcement: AC-03, AC-04, AC-06 (90%)
- 3-3 SR 2.4 Mobile code: SC-18 (85%)
- 3-3 SR 2.6 Remote session termination: AC-17 (50%)
- 3-3 SR 2.8 Auditable events: AU-02, AU-03, AU-12 (85%)
- 3-3 SR 2.9 Audit storage capacity: AU-04, AU-05 (90%)
- 3-3 SR 2.11 Timestamps: AU-08, SC-45 (92%)
- 3-3 SR 3.1 Communication integrity: SC-08, SI-07, CM-14 (88%)
- 3-3 SR 3.4 Software and information integrity: CM-14, SI-07, SI-16, CM-03 (88%)
- 3-3 SR 3.5 Input validation: SI-10 (85%)
- 3-3 SR 4.1 Information confidentiality: SC-28, SC-08, AC-03, AC-17 (85%)
- 3-3 SR 5.1 Network segmentation: SC-07, SC-32, AC-04, SC-46 (78%)
- 3-3 SR 5.2 Zone boundary protection: SC-07, SC-46 (82%)
- 3-3 SR 6.1 Audit log accessibility: AU-09, AU-06 (85%)
- 3-3 SR 6.2 Continuous monitoring: CA-07, SI-04, SC-48 (78%)
- 3-3 SR 7.1 Denial of service protection: SC-05, SC-24 (72%)
- 3-3 SR 7.2 Resource management: AU-04, SC-05, CP-02, SC-06 (78%)
- 3-3 SR 7.3 Control system backup: CP-09, CP-06, CP-10 (80%)
- 3-3 SR 7.4 Control system recovery and reconstitution: CP-10, IR-04, SC-24 (78%)
- 3-3 SR 7.6 Network and security configuration settings: CM-02, CM-06, CM-07, PL-10, PL-11, CM-03 (88%)
- 3-3 SR 7.7 Least functionality: CM-07 (80%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=iec_62443
- Control-to-clause mappings as JSON: /api/v1/frameworks/iec_62443?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/iec-62443.json
- Page for people: /frameworks/iec-62443/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
