ISA/IEC 62443IndustrialGlobalManufacturing / Industrial

ISA/IEC 62443 Industrial Automation and Control Systems Security

International standard series for industrial automation security. Covers security lifecycle for industrial control systems and Industry 4.0 environments.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

ISA/IEC 62443SR 2.8A record of access

Auditable Events

Control systems MUST generate audit records for security-relevant events.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

ISA/IEC 62443SR 2.9Integrity of the recordRetention and availability

Audit Storage Capacity

REQUIRES sufficient storage and protection for audit logs from PLCs and SCADA systems.

A requirement like this is about the record surviving the person who would rather it did not, which means the audit trail has to be protected as carefully as the data. File activity monitoring hashes the datafiles, the transaction logs, the backups, and the audit trail itself with XXH3, then baselines them — so an alteration or a deletion is evident rather than inferred, and it is attributed to the session and OS user behind it. Because the same platform holds the query trail, a destructive statement and the file-level change it produced are two views of one event rather than two investigations.

ISA/IEC 62443SR 2.10Routing and evidencing the responseIntegrity of the record

Response to Audit Failures

Systems MUST alert upon audit processing failure and protect audit integrity.

Findings route by severity to Slack, Teams, email, PagerDuty, or your SIEM, and escalate automatically when nobody acknowledges them and again when nobody resolves them. Every alert arrives with the query, the identity, and the data classification already attached, so the response starts with context rather than with an investigation. The acknowledge-to-resolve history is retained, which is what evidences that the procedure was followed. Your ticketing system stays where it is — what this produces is a finding worth opening a ticket for.

ISA/IEC 62443SR 6.1Least privilege and privileged useAttribution to an individual

Audit Log Accessibility

Authorized personnel MUST be able to access and review audit logs.

Authorisation is configured in the database; proving it holds is what this requirement actually needs. Vulnerability scanning surfaces excessive privilege and role sprawl, default and weak credentials, and stale or orphaned accounts — including privilege inherited through nested roles, which is where least-privilege reviews usually go wrong. Real-time SQL auditing then shows which of those grants were exercised, so an access review reflects observed use rather than intent.

What ISA/IEC 62443 covers

This instrument defines no data category of its own. Governs industrial automation and control SYSTEMS, organised by zones, conduits and security levels rather than by data class.

How ISA/IEC 62443 is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by Certification bodies where certification is sought; otherwise nobody.

A voluntary standard. No regulator enforces it.

ISA/IEC 62443 is the reference standard for industrial automation and control system security. It is voluntary in itself, and it is heavily referenced: EU product regulation, national critical infrastructure rules, and asset-owner procurement all point at it, and those are what carry consequences.

Where a regulation adopts 62443 by reference, the obligation and the penalty belong to that regulation.

Uncapped exposure that sits outside this instrument

These come from company law rather than from ISA/IEC 62443, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for ISA/IEC 62443,
not configured for it afterwards

Policy Template

ICS/SCADA Monitoring

Audit PLCs and SCADA databases in automated factories

Report

IEC 62443 Compliance Report

Real-time OT security log documentation

Classification

Industrial Data Patterns

Identify PLC programming, HMI data, and process control

Alert

ICS Security Event

Alert on unauthorized access to industrial control systems

Walk into the ISA/IEC 62443 audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment