IEC 62443-2-2 published
IEC 62443-2-2 has now been published by IEC- International Electrotechnical Commission. This is part of the IEC 62443 set of standards and relates to Industrial Cybersecurity (cyber security of Industrial Automation & Control Systems, known as IACS for short).
However, IEC 62443 development has been uneven- not all parts have been published, but some parts are already in their second editions!
What is IEC 62443?
IEC 62443 is a set of Standards, Technical Reports and other documents that relate to cyber security of Industrial Control Systems . These systems are also called OT systems where OT stands for Operational Technology, which means computer based systems that monitor and control physical objects such as valves, actuators, motors, etc. In contrast IT systems are Information Technology systems that dela with only data processing, they are not directly connected to physical equipment.
Refer to the Free IEC 62443 guide here OR download the IEC 62443 book here to know more.
IEC 62443 changes
The original structure of IEC 62443 was four sections and each section had several parts. The numbering was IEC 62443-x-y where x was from 1 to 4. y could be anything from 1 onward. Thus the first part of IEC 62443 is IEC 62443-1-1 and other parts have similar numbers (e.g. IEC 62443-2-1 is for Security Program for Asset Owners, IEC 62443-2-4 is about a Security Program for OT system suppliers and so on). The below diagram shows the earlier structure.

Since the year 2024 the structure has changed from 4 sections to now 6 sections. So now we have parts numbered like IEC 62443-6-1 and such. Below is the diagram that shows the new structure.

What is IEC 62443-2-2?
IEC 62443-2-2 is titled as Publicly Available Specification- IACS security protection scheme. According to language in the standard, ” This part of IEC 62443 provides guidance on the development, validation, operation, and maintenance of a set of technical, physical, and process security measures called Security Protection Scheme (SPS). The document’s goal is to provide the asset owner implementing an IACS Security Program (SP) with mechanisms and procedures to ensure that the design, implementation and operation of an SPS manage the risks resulting from cyberthreats to each of the IACS included in its operating facility“.

What we gather from this description that this will provide more details than given in IEC 62443-2-1 (which is about a Security Program for Asset Owners). Apparently IEC 62443-2-1 is a broad framework and this document IEC 62443-2-2 will provide more detailed specifications related to the framework. Hence, this is more applicable to Asset Owners and EPC (Engineering Procurement and Construction) companies who build plants and facilities for asset owners (including specifying, installing/commissioning/testing the IACS that control and monitor the plant operations), so that they are protected from cyber threats.
Where can I learn more about IEC 62443 & Industrial Cybersecurity?
You can take the Abhisam Certified Industrial Cybersecurity Professional (CICP) course. Not only will you learn about Industrial & OT Cybersecurity, IEC 62443 and other related stuff like supply chain security- you will also earn the title of CICP that you can use. Also the CICP course gets updated periodically as IEC 62443 standards change, so your knowledge does not become obsolete. Unlike other course providers who charge you four times more for basic courses.
This is the most current and cost effective courses out there, that also confer a title. This helps you increase your status too, in addition to making you knowledgeable.


