IEC 62443 Isn't a Checklist: Compliance vs. Implementation
IEC 62443 is not a checklist. Here is the difference between compliance and implementation — and why it matters.
Two Very Different Things That Look the Same on Paper
Compliance: a vendor's datasheet says the PLC supports role-based access control. Implementation: role-based access control is actually configured and tested.
Compliance: the zone-conduit diagram exists in the HAZOP documentation. Implementation: the physical network actually matches the diagram.
Most audits check documentation. An attacker checks implementation.
A Practical Diagnostic
One practical diagnostic: pull the network diagram for your plant and physically walk one zone. Count how many unlisted connections you find.
We've done this with engineers at three facilities. The average: 4 undocumented connections per zone. None were in any documentation. All were exploitable.
Where the Real Problem Sits
IEC 62443 isn't hard to comply with on paper. That's not the problem. The problem is that paper compliance doesn't change what an attacker can do once they're inside your network.
Start Here
Start with authentication. Pull the list of user accounts on your SCADA server. If any of them are shared accounts, you have an SL1 system dressed as SL2.
Need Help With Compliance?
Talk to Prazamana about machine safety standards and CE marking for your equipment.