L-com

Industrial Network Security Compliance: IEC 62443, NERC CIP & NIST CSF Explained

By Dustin Guttadauro, Product Line Manager - Telecom & Fiber, Infinite Electronics  

 

Industrial organizations are rarely governed by a single cybersecurity framework. A manufacturer may encounter IEC 62443 requirements from customers, follow the NIST Cybersecurity Framework (CSF) to guide its security program, and support utility operations subject to North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) standards. Although these frameworks share many common objectives, they differ in scope, terminology, implementation, and compliance requirements, making it difficult to understand where they overlap and how they should be applied.  

  

Rather than treating IEC 62443, NERC CIP, and NIST CSF as competing approaches, organizations should view them as complementary tools. Understanding the purpose of each framework helps security teams prioritize investments, simplify compliance efforts, and build industrial networks that support both operational resilience and regulatory expectations. This guide compares the three frameworks, explains where they align, and highlights the physical infrastructure controls that support effective industrial network security. 

 

Key Takeaways 

•   Industrial network security compliance across IEC 62443, NERC CIP, and NIST CSF all require physical controls — locked enclosures, cable management, tamper detection, surge protection, and physical zone boundary enforcement — not just software and network controls. Physical hardware choices satisfy specific, named requirements in all three frameworks. 

•   IEC 62443 is the international OT security standard used across manufacturing, utilities, and oil & gas worldwide; NERC CIP is the legally mandatory US bulk electric system standard with up to $1M/day penalties; NIST CSF is the outcomes-based framework widely adopted as a governance structure across sectors. The three are complementary, not competing. 

•   The compliance gap most consistently found in audits is not a software control failure — it's inadequate physical security: network hardware in unlocked enclosures, cable runs outside defined security perimeters, missing tamper detection on high-consequence systems, and no documentation connecting physical infrastructure to compliance requirements. 

•   A compliance-to-physical-controls mapping table — connecting specific IEC 62443 requirements, NERC CIP standards, and NIST CSF controls to specific hardware categories (surge protectors, shielded cables, fiber isolation, secure enclosures) — is the gap in how compliance programs are typically documented, and it's what this article provides.  

 

What are the three dominant industrial security compliance frameworks?What are the three dominant industrial security compliance frameworks? 

Three frameworks dominate industrial network security compliance across most regulated industries. Understanding how they relate to each other determines how to structure a compliance program when more than one applies to your organization — which is common. 

 

IEC 62443IEC 62443 

IEC 62443 is the international standard series for Industrial Automation and Control System (IACS) security, developed by ISA (formerly ISA-99) and published jointly as IEC 62443. It applies to any industrial control system environment globally — manufacturing, utilities, oil and gas, pharmaceuticals, water treatment, and transportation infrastructure. It's not legally mandatory in most jurisdictions, but it has become contractually mandatory in many sectors through major customer requirements, cyber insurance conditions, and increasingly, regulatory reference. 

IEC 62443 is organized into four series covering general concepts (Series 1), policies and procedures (Series 2), system-level requirements (Series 3), and component-level requirements (Series 4). For practitioners implementing a compliance program, the most relevant parts are 3-2 (risk assessment and zone design), 3-3 (system security requirements at SL1–SL4), and 4-2 (component requirements for procured hardware). 

 

NERC CIPNERC CIP 

NERC Critical Infrastructure Protection standards are legally mandatory for reliability standards for the Bulk Electric System in North America, enforced by the Federal Energy Regulatory Commission (FERC) under FERC Order 791. They apply to registered entities — utilities, transmission operators, generation operators, and distribution providers above defined capacity thresholds. Violations carry penalties up to $1 million per violation per day. 

NERC CIP covers 13 standards (CIP-002 through CIP-013) addressing everything from asset categorization to supply chain risk management. For OT network infrastructure, the most directly relevant are CIP-005 (Electronic Security Perimeters), CIP-006 (Physical Security), and CIP-007 (Systems Security Management) — detailed in our NERC CIP-specific guide linked at the end of this article. 

 

NIST CSF 2.0NIST CSF 2.0 

The NIST Cybersecurity Framework, released in version 2.0 in February 2024, organizes security activities around six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It's voluntary, sector-agnostic, and outcome-oriented rather than prescriptive — it tells organizations what to achieve, not how to achieve it. NIST SP 800-82 (Guide to Industrial Control Systems Security) provides OT-specific implementation guidance aligned to the CSF. 

NIST CSF is increasingly referenced in US government requirements, executive orders, and cyber insurance applications. Organizations that use it as a governance framework often implement IEC 62443 or NERC CIP to provide the technical specificity the CSF doesn't prescribe. 

 

How do IEC 62443, NERC CIP, and NIST CSF compare?How do IEC 62443, NERC CIP, and NIST CSF compare? 

The table below compares the three frameworks across nine dimensions relevant to OT compliance program design. The physical layer row is highlighted because it reveals a consistent difference: IEC 62443 and NERC CIP both make explicit physical hardware requirements; NIST CSF addresses physical controls but less specifically. 

  

Dimension 

IEC 62443 

NERC CIP 

NIST CSF 2.0 

Scope 

Industrial automation and control systems globally — manufacturing, utilities, oil & gas, any IACS environment 

Bulk Electric System (BES) in North America — regulated under FERC; mandatory for registered entities 

Any organization, the US government endorses for critical infrastructure is widely adopted globally 

Authority 

Voluntary international standard; mandated by contract or regulation in some sectors 

Legally mandatory for NERC-registered entities under FERC Order 791; up to $1M/day penalties 

Voluntary framework; referenced in US executive orders; increasingly required by insurers and supply chain contracts 

Primary model 

Zone-and-conduit architecture with Security Levels 1–4; asset owner, integrator, and supplier roles defined separately 

Standard-by-standard mandatory requirements (CIP-002 through CIP-013); evidence-based compliance 

Function-based: Govern, Identify, Protect, Detect, Respond, Recover — outcomes-oriented, not prescriptive 

Physical security focus 

Explicit: physical access controls in IEC 62443-3-3 (SC-7), component physical requirements in 4-2; conduit physical media selection 

Explicit: CIP-006 Physical Security of BES Cyber Systems — PSP definition, access logs, tamper detection required 

Moderate: PR.AC (physical access), PR.PT (protective technology) subcategories; less prescriptive than IEC 62443 

OT-specific guidance 

Native OT standard — designed specifically for ICS environments; addresses legacy devices, availability priority, protocol-specific requirements 

Fully OT-specific — developed for electric utility control systems; substation and control center environments 

Sector-agnostic but adaptable, NIST SP 800-82 provides OT-specific implementation guidance 

Physical-layer controls 

Explicitly referenced: physical media for conduits, zone boundary physical enforcement, surge protection, shielded cabling in high-EMI environments 

CIP-006 requires PSP definition, locked cabinets, physical access logs, tamper detection — physical hardware requirements 

Physical controls are addressed under PR.AC and PR. PT: less specific than IEC 62443 and NERC CIP on hardware types 

Audit/evidence approach 

Gap assessment against target SL; self-assessment or third-party; IEC 62443 certification available 

Mandatory periodic audits by the regional entity; evidence-based — specific documents, configurations, and records required 

Self-assessment oriented; CISA provides assessment tools; third-party assessment increasingly required by insurers 

Where to start 

Risk assessment (IEC 62443-3-2) → zone/conduit design → gap assessment against SL target 

CIP-002 categorization first (scoping) → CIP-005/006/007 technical controls → documentation 

Identify function first (asset inventory, risk assessment) → build towards Protect, Detect, Respond 

  

The interaction between frameworks matters for organizations subject to more than one. A utility subject to NERC CIP that also operates manufacturing assets may find IEC 62443 required for those assets through customer contracts. Using NIST CSF as a governance overlay that maps to both is a common architecture: CSF functions provide the executive reporting structure; IEC 62443 and NERC CIP provide the technical control specifications underneath. 

 

How do physical infrastructure controls satisfy framework requirements?How do physical infrastructure controls satisfy framework requirements? 

Compliance programmers consistently underspecify physical infrastructure controls. Firewall rules, certificate policies, and logging configurations are documented in detail. The locked enclosure that protects the firewall hardware, the shielded cable that keeps the firewall's packet inspection accurate, and the surge protector that prevents the firewall from failing in a pass-through state — these are often absent from compliance documentation entirely. 

All three frameworks have explicit or implicit requirements that physical hardware controls satisfy. The table below maps seven physical control categories to specific requirements in IEC 62443, NERC CIP, and NIST CSF, with the relevant L-com product category as the hardware implementation. 

  

Physical control 

IEC 62443 control reference 

NERC CIP control reference 

NIST CSF control reference 

L-com product 

Locked industrial enclosures for network hardware 

IEC 62443-3-3 SC-7 (physical access control at zone boundary); 4-2 PE-1 (physical access to component) 

CIP-006 R1.2 (physical access to PSP entry points); R1.3 (individual credentials) 

PR.AC-2 (physical access management); PR.PT-4 (communications and control networks protected) 

secure industrial enclosures 

Tamper switches wired to SCADA alarm 

IEC 62443-3-3 PE-1 (physical access detection at high SL zones) 

CIP-006 R1.6 (unauthorized access attempts detected and reported — high-impact BCS) 

DE.CM-2 (physical environment monitoring); PR.AC-2 (physical access control) 

secure industrial enclosures 

Shielded Ethernet cable (STP/FTP/S-FTP) on all field device runs 

IEC 62443-3-3 SC-3 (communication integrity — physical signal quality contributes to integrity on OT conduits) 

CIP-006 R1 general (cable management within PSP); CIP-007 R4 (event logging — clean signal improves log accuracy) 

PR.DS-2 (data in transit); implicit under PR.PT-4 (communications protected) 

shielded industrial Ethernet cables 

Ethernet surge protectors on all field device copper ports 

IEC 62443-3-3 SC-3 (communication integrity — prevents port failure that could cause fail-open) and PE-1 (physical integrity of the network component) 

CIP-006 R1 (physical protection of BCS hardware); CIP-007 R1 (hardware integrity — damaged ports create unauthorized service paths) 

PR.PT-4 (communications and control networks); implicit PR.MA-1 (maintenance of assets) 

Ethernet surge protectors 

Fiber optic at IT/OT zone boundary crossings 

IEC 62443-3-3 SC-7 (zone boundary conduit control — fiber enforces physical separation); 3-2 zone boundary conduit specification 

CIP-005 R1 (Electronic Security Perimeter boundary — fiber provides physical ESP enforcement); CIP-006 R1 (PSP boundary management) 

PR.AC-5 (network integrity including network segregation); PR.PT-4 (communications and control networks) 

fiber optic isolation solutions 

Fiber optic for building-to-building outdoor connections 

IEC 62443-3-3 SC-3 (conduit integrity — ground loop elimination and surge immunity on conduit); zone boundary conduit specification 

CIP-006 R1 (physical security of communications paths between PSPs); implicit CIP-005 R1 (ESP boundary) 

PR.AC-5 (network integrity); PR.DS-2 (data in transit protection) 

fiber optic isolation solutions 

Sealed cable entries and cable gland fittings on all enclosures 

IEC 62443-3-3 PE-1 (physical access to zone — unsealed entries are uncontrolled access points) 

CIP-006 R1.1 (Physical Security Perimeter definition — all openings must be identified and controlled) 

PR.AC-2 (physical access management — uncontrolled cable entries are physical access gaps) 

secure industrial enclosures 

  

The conduit physical media row (shielded cable) addresses a requirement that practitioners frequently misread as a software concern: IEC 62443-3-3 SC-3 (Communication Integrity) is typically implemented via TLS encryption and protocol inspection — but in OT environments where legacy protocols carry unencrypted traffic, the physical signal quality on the cable determines the integrity of the traffic that software tools inspect. EMI-induced bit errors in Modbus frames are a communication integrity failure that encryption and DPI cannot fix.  

 

IEC 62443 compliance in practice: zones, conduits, and security levelsIEC 62443 compliance in practice: zones, conduits, and security levels 

IEC 62443's zone-and-conduit model is the architectural core that everything else builds on. Zones are logical groupings of assets with similar security requirements; conduits are the controlled communication paths between zones. Every conduit must have a defined security level and specific controls. 

 

Setting the target security levelSetting the target security level 

Security levels in IEC 62443 are assigned based on the threat actor assumed and the consequence of compromise. SL1 addresses casual or unintentional threats; SL2 addresses intentional attacks with simple means and low motivation (the realistic threat for most manufacturers); SL3 addresses sophisticated attacks; SL4 addresses nation-state level threats. Most manufacturing environments should target SL2 for operational zones and SL3 for safety instrumented systems. 

The gap between the current security level (SL-A, Achieved) and target (SL-T, Target) is what the compliance program remediates. Physical controls — enclosures, cable shielding, fiber at zone boundaries, surge protection — are part of closing that gap, and they're typically specified at the zone design stage rather than discovered during implementation. 

 

Conduit physical media as a compliance specificationConduit physical media as a compliance specification 

IEC 62443-3-2 requires that conduit security levels be defined and that conduit controls be specified. Physical media selection is part of the conduit specification. A conduit at SL2 between a field zone and a control zone should specify the cable type (shielded industrial Ethernet for all runs through high-EMI areas), the boundary enforcement mechanism (fiber optic isolation at zone boundary crossings), and the field device port protection (Ethernet surge protectors on all copper entry points). These are compliance artifacts, not just engineering decisions. 

 

NERC CIP compliance in practice: scoping, physical security, and audit evidence 

NERC CIP compliance is evidence-based. Auditors from the regional entity don't evaluate intent or effort — they compare documented evidence against requirements language. A correctly configured physical security setup that isn't documented in the Physical Security Plan doesn't satisfy CIP-006. Documentation and physical reality must match. 

 

Scoping under CIP-002Scoping under CIP-002 

CIP-002 categorization determines what's in scope for the detailed technical requirements. High-impact BCS receive the full set of requirements; Medium-impact BCS receive most of them; Low-impact BCS receive a reduced set. The scoping decision is consequential — a miscategorized asset that should be Medium but is treated as Low is non-compliant for all the Medium-impact requirements that weren't applied to it. 

Scoping must be re-evaluated after topology changes. A new communication path between a previously scoped and a previously unscored system, or a firmware update that enables a new communication protocol, can change categorization. The change management process must include a CIP-002 scoping review as a required step. 

 

Physical security evidence requirementsPhysical security evidence requirements 

CIP-006 physical security compliance requires specific documented evidence. The Physical Security Plan must describe the PSP boundary, all entry and exit points, the access control mechanisms at each point, and (for high-impact BCS) the tamper detection systems.Secure industrial enclosures with keyed access satisfy the R1.2 access control requirement; tamper switches wired to SCADA or alarm systems satisfy R1.6 for high-impact BCS. Both must be documented in the Physical Security Plan — the hardware alone doesn't satisfy the requirement without documentation. 

Auditors conduct physical site walks as part of CIP-006 assessments. They compare the physical security plan against what they observe in the field. Common findings from physical site walks: cable runs outside the documented PSP boundary, enclosure doors that are unlocked or use shared codes rather than individual credentials, and tamper switches that are installed but not connected to a monitored alarm. 

 

 NIST CSF 2.0 in practice: using the framework as an OT compliance foundation 

NIST CSF 2.0's six functions — Govern, Identify, Protect, Detect, Respond, Recover — provide a governance structure that organizations use to organize and communicate their security programmed. For OT environments, the framework is most useful as the executive reporting layer on top of the more technically specific IEC 62443 or NERC CIP controls. 

Mapping physical controls to CSF functionsMapping physical controls to CSF functions 

The Protect function (PR) is where most physical controls map in NIST CSF. PR.AC (Access Control) includes physical access management (PR.AC-2) and network segregation (PR.AC-5). PR.PT (Protective Technology) includes communications and control network protection (PR.PT-4). PR.DS (Data Security) includes protection of data in transit (PR.DS-2). 

Physical controls — enclosures, cable shielding, fiber isolation — satisfy multiple CSF subcategories simultaneously. A fiber optic zone boundary satisfies PR.AC-5 (network segregation), PR.DS-2 (data in transit) and contributes to the Detect function by making physical tap detection possible through optical power monitoring. 

 

NIST SP 800-82 for OT implementation guidanceNIST SP 800-82 for OT implementation guidance 

NIST SP 800-82 (Guide to Industrial Control Systems Security) is the companion document that provides OT-specific implementation guidance for the CSF. It covers network architecture, physical security, patch management, and incident response for ICS environments. For organizations using NIST CSF as their primary framework but needing more OT-specific technical guidance, SP 800-82 provides that specificity without the mandatory compliance burden of NERC CIP.  

 

What are the most common industrial network security compliance gaps?What are the most common industrial network security compliance gaps? 

The table below categorizes the compliance gaps that appear most frequently in IEC 62443 gap assessments and NERC CIP audit findings. The NERC CIP column is shown in red because NERC CIP gaps have financial penalty consequences; IEC 62443 gaps are shown in amber as risk exposure. The mitigation column applies to both. 

  

Gap category 

IEC 62443 finding 

NERC CIP finding 

Mitigation 

Scope / asset inventory 

Assets added to OT network after initial zone design not re-categorized; zone map outdated 

BES Cyber Assets not identified in CIP-002 categorization; scope updated irregularly after topology changes 

Quarterly asset review process; passive OT network monitoring (Dragos, Claroty) for continuous discovery; zone map version-controlled 

Physical access — enclosures 

Network hardware in open racks or unlocked cabinets; no tamper detection on high-consequence equipment 

PSP not formally defined; equipment outside documented PSP; no tamper detection on High impact BCS 

All OT network hardware in locked NEMA-rated enclosures; tamper switches on critical cabinets; PSP documentation updated to match physical reality 

Physical access — cable management 

Cable runs outside the zone boundary not documented; network cables in accessible areas without conduit protection 

Network cables outside PSP without documented compensating controls; open knockouts on PSP enclosures 

Cable audit against zone map; all cable entries via sealed cable glands; open knockouts plugged; document any runs outside PSP with compensating controls 

Conduit physical media 

Copper cable at zone boundaries where fiber is specified; unshielded cable in high-EMI areas creating signal integrity problems flagged as communication integrity gap 

N/A (NERC CIP doesn't specify cable type) — but cable runs outside PSP are a CIP-006 gap 

Fiber at all IT/OT zone boundaries; shielded cable (STP/FTP) in all high-EMI runs; surge protectors on all field device copper ports 

Remote access / MFA 

Remote access paths not fully inventoried; vendor access without MFA; no session logging 

CIP-005 R2.1: all Interactive Remote Access requires MFA — vendor VPNs, backup access paths are missing 

Audit all remote access paths including vendor connections; enforce MFA on every path; log all sessions; revoke vendor access after each maintenance event 

Patch management documentation 

Firmware inventory incomplete; patch evaluation not documented; devices treated as out-of-scope for patching 

CIP-007 R2: security patches evaluated within 35 days of release; evidence not maintained; firmware excluded from patch program 

Firmware version inventory for every network device; subscribe to vendor security bulletins; document evaluation and disposition within 35 days 

Security event logging 

Logging not configured on OT network devices; logs local-only (not forwarded off-device); retention <90 days 

CIP-007 R4: security event logs must be retained 90 days; forwarding to central collector not configured 

Enable syslog on all managed switches, firewalls, and gateways; forward to central SIEM or log aggregator; verify 90-day retention 

Documentation currency 

Zone/conduit map, network topology diagrams, and physical security plans have not been updated after changes 

Network topology, ESP documentation, and Physical Security Plan describe design that no longer matches deployed configuration 

The change management process requires documentation update before any network or physical change is closed; quarterly documentation audit 

  

The physical access and cable management rows account for a disproportionate share of audit findings relative to the remediation effort required. Installing a keyed enclosure for network hardware, sealing cable knockouts, and running a shielded cable instead of an unshielded cable are straightforward physical changes. Their absence in compliance programmed is a procurement and specification process failure — the right hardware needs to be in the bill of materials from the project design stage. 

 

How do you prepare for an industrial network security compliance audit? 

Audit preparation starts 90 days before the scheduled assessment, not 90 minutes before. The most common audit outcome that surprises organizations is not that their controls are non-compliant — it's that their documentation doesn't reflect the controls they've deployed. Physical security that isn't documented in the Physical Security Plan, firewall rules that aren't in the network topology documentation, and firmware versions that don't appear in the patch management records are all findings. 

 

OT Security Audit Preparation Checklist 

  1. Keep the Network Topology Diagram Current: Ensure the network topology diagram accurately reflects the deployed environment, is version-controlled, and is updated within 30 days of any network change.  
  1. Document Zone-and-Conduit Architecture: Complete an IEC 62443 zone-and-conduit map or a NERC CIP ESP/PSP diagram to clearly define the audit scope and security boundaries.  
  1. Maintain a Complete Asset Inventory: Record every OT asset, including its make, model, firmware version, IP address, and zone assignment. Passive OT monitoring tools can help keep the inventory accurate.  
  1. Document the Physical Security Plan: Maintain an up-to-date Physical Security Plan (PSP) that identifies all protected boundaries, entry points, and access control mechanisms, as auditors typically validate these during site inspections.  
  1. Review Security Policies Annually: Ensure all cybersecurity policies are documented and have been reviewed and approved within the previous 12 months. Retain evidence of each review.  
  1. Verify Locked Industrial Enclosures: Confirm that all OT networking and control equipment is installed in rated, lockable industrial enclosures. Inspect cabinets before the audit to identify and correct any physical security issues.  
  1. Seal All Cable Entry Points: Verify that all unused knockouts are sealed and every active cable entry uses appropriate cable glands to protect against environmental hazards and unauthorized access.  
  1. Test Tamper Detection Systems: Confirm that cabinet tamper switches are installed, functioning correctly, and connected to monitored alarm systems. Perform a functional test and verify that alerts are received.  
  1. Inspect Surge Protection Devices: Ensure Ethernet surge protectors are installed on all field device copper connections and cable entry points. Document inspections and maintenance records for audit evidence.  
  1. Verify Fiber Isolation at IT/OT Boundaries: Confirm that fiber links and media converters are operating correctly at IT/OT zone boundaries. Document all fiber boundary locations and verify link status.  
  1. Review Firewall Configurations: Ensure firewall rule documentation matches the live device configuration. Auditors commonly compare documented policies with actual firewall settings.  
  1. Validate Multi-Factor Authentication (MFA): Test every remote access pathway to confirm MFA is enforced consistently. Record the testing results as audit evidence.  
  1. Verify Centralized Security Logging: Confirm that security events are forwarded to a centralized logging or SIEM platform, and that logs are retained for at least 90 days (about 3 months). Prepare sample log exports for the audit.  
  1. Maintain Firmware and Patch Records: Keep up-to-date inventory of firmware versions for all OT devices and document patch evaluations and upgrade decisions made during the previous 12 months.  
  1. Eliminate Default Credentials: Verify that no Business-Critical System (BCS) devices are still using factory-default usernames or passwords. Compare configurations against vendor default credential lists.  
  1. Review User Accounts: Ensure all user accounts belong to authorized personnel only. Remove accounts for former employees and contractors, perform an account review within 30 days of the audit, and retain documentation of the review. 

  

Physical items 6–10 in this checklist are the ones most often deferred until the week before an audit and therefore most often incomplete. Network hardware enclosures, cable entry sealing, tamper switches, surge protectors, and fiber boundary installations are physical changes that require procurement lead time, scheduled maintenance windows, and sometimes contractor access. Add them to a 90-day pre-audit project plan, not a 2-week one. 

 

Which framework should your organization use, and can you combine them?organization use, and can you combine them? 

The framework selection question has a simpler answer than most compliance discussions suggest: 

  • If you're a US utility or grid operator: NERC CIP is not optional. Start there. Use NIST CSF as the governance overlay for executive reporting. 
  • If you're in manufacturing, oil & gas, pharma, or other regulated industry: IEC 62443 is the technical standard. NIST CSF as the governance framework. Check whether your major customers or cyber insurers require IEC 62443 compliance or certification. 
  • If you're in both (utility with manufacturing assets, energy company with production facilities): NERC CIP for the BES-connected systems; IEC 62443 for the manufacturing/production OT systems; NIST CSF as the unifying governance framework across both. 
  • If you're unsure: start with NIST CSF's Identify function (asset inventory and risk assessment). The output of that function tells you what assets you have and what their risk exposure is, which determines which technical framework requirements apply. 

  

The frameworks are designed to be used together. IEC 62443 and NIST CSF explicitly cross-reference each other in their current versions. NERC CIP, while independently prescribed, maps naturally to IEC 62443's zone-and-conduit model and NIST CSF's functions. An organization that builds a compliance program on IEC 62443 technical controls governed by NIST CSF has a program that satisfies most of the intent of all three frameworks — and with NERC CIP added for the specific BES-connected assets, covers the full regulated scope. 

 

Physical infrastructure is where compliance programs have the most undocumented gaps 

Every framework covered in this article makes explicit or implicit requirements for physical infrastructure controls — locked enclosures with individual access credentials, cable management within defined security perimeters, surge protection on hardware that could fail in a security-relevant state, and fiber isolation at zone boundaries. These requirements are consistently under-documented in compliance programs — they appear in the Physical Security Plan gap list, not in the BOM. 

L-com's physical-layer security products directly satisfy the hardware requirements that IEC 62443, NERC CIP, and NIST CSF specify:Ethernet surge protectors for conduit integrity and hardware protection,shielded industrial Ethernet cables for EMI-compliant conduit runs,fiber optic isolation solutions for zone boundary physical enforcement, andsecure industrial enclosures for physical security perimeter implementation. Include them in the compliance project BOM at the design stage — they're compliance artifacts as much as they are infrastructure components. 

 

Frequently Asked QuestionsFrequently Asked Questions 

Q1: What is IEC 62443, and who must comply?Q1: What is IEC 62443, and who must comply? 

A: IEC 62443 is the international standard series for Industrial Automation and Control System (IACS) security, published by ISA and IEC. It's a voluntary standard — there is no global legal requirement to comply with it. However, compliance has become effectively mandatory in many situations through commercial channels: major industrial customers increasingly require IEC 62443 compliance or certification from suppliers; cyber insurers are beginning to require it as a condition of OT cyber coverage; and regulated sectors in some jurisdictions reference it in compliance requirements. 

Q2: What is the difference between NERC CIP and IEC 62443? 

A: NERC CIP is a set of legally mandatory reliability standards for the bulk electric system in North America, enforced by FERC with financial penalties up to $1 million per violation per day. IEC 62443 is a voluntary international standard for all IACS environments globally. NERC CIP is prescriptive and evidence-based — specific documents, configurations, and records must exist to demonstrate compliance. IEC 62443 is risk-based and uses security levels — the organization assesses its threat environment, sets target security levels, and remediates gaps.    

Q3: How does NIST CSF relate to OT security compliance?Q3: How does NIST CSF relate to OT security compliance? 

A: NIST CSF (Cybersecurity Framework) provides a governance and risk management structure organized around six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It's technology- and sector-agnostic, making it a useful executive reporting and governance layer over more technically specific OT standards. Organizations commonly use NIST CSF as the unifying framework that maps to their OT-specific compliance requirements: the CSF functions organize executive reporting; IEC 62443 or NERC CIP provide the technical control specificity. NIST SP 800-82 (Guide to ICS Security) provides OT-specific implementation guidance that maps directly to CSF subcategories, giving practitioners the technical detail the CSF itself doesn't prescribe. 

Resources

Search Entries