Study tracks
IEC 62443 Track
A path into industrial and operational-technology (OT) security built around ISA/IEC 62443. It follows the order of ISA's Cybersecurity Fundamentals Specialist certificate, the entry point of the ISA/IEC 62443 certificate programme, then adds the risk-assessment and design material the next certificates build on.
1 min read
4 sections
Part 1 — OT foundations
- Why 62443 matters — the incidents that shaped OT security
- IT versus OT priorities — safety and availability first
- The Purdue model — levels 0–5 and the industrial DMZ
- Key components — PLC, RTU, HMI, SCADA, DCS, SIS, historian
- Converged and industrial protocols — why Modbus and DNP3 need compensating controls
Part 2 — The standard (Fundamentals Specialist)
- How the series is organised — general, policies, system, component
- Roles — asset owner, service provider, product supplier
- Zones and conduits
- Security levels SL 0–4 — SL-T, SL-C, SL-A
- The seven foundational requirements
- Maturity levels
- Certification — ISASecure, the IECEE scheme and the individual certificate path
Part 3 — Risk assessment and design (Risk Assessment and Design Specialist)
- Risk assessment and design, 62443-3-2 — system under consideration to cybersecurity requirements specification
- Risk management fundamentals — likelihood, impact, treatment
- Network segmentation — firewalls, DMZs, micro-segmentation
- Secure development for suppliers, 62443-4-1
Part 4 — Operate and respond (Maintenance Specialist)
- Attacks and defences in practice — remote access, living off the land, passive monitoring
- Change, configuration and patch management
- Business continuity and DR — offline backups of PLC logic and configurations
- IR psychology and digital forensics — adapted for plants where safety outranks evidence
- NIS2 — the regulatory driver for EU operators