IEC 62443-3-3 Security Level Mapping Workbook
The IEC 62443-3-3 Security Level Mapping Workbook is an Excel-based tool designed to support the systematic identification, analysis, and assignment of Security Levels (SL-C and SL-T) to industrial automation and control systems (IACS) in accordance with the IEC 62443-3-3 standard. It facilitates risk-informed security requirements derivation by mapping threat consequences and likelihoods to target Security Levels for both capabilities (SL-C) and threats (SL-T). The workbook enables consistent, auditable, and traceable alignment between organizational risk tolerance and technical security controls.
π Overview
π Key Components
π― Applications
- β SCADA system integration and hardening
- β IEC 62443 compliance gap analysis and certification preparation
- β OT security requirements elicitation for brownfield and greenfield projects
π Key Formulas
Security Level β Consequence (SL-C)
SL-C = f(Consequence_Score)
Maps qualitative consequence scores (1β4) to Security Level targets (1β4) based on predefined consequence thresholds per impact category (e.g., Safety: Score β₯3 β SL-C β₯3)
Security Level β Threat (SL-T)
SL-T = f(Likelihood_Score, Consequence_Score)
Determines required threat-specific security level using the IEC 62443-3-3 4Γ4 risk matrix, where rows = Likelihood (1β4) and columns = Consequence (1β4), yielding SL-T = max(1, min(4, row + column β 1))
Overall Target Security Level (SL)
SL = max(SL-C, SL-T)
Selects the higher of the consequence-derived (SL-C) and threat-derived (SL-T) levels to define the minimum required security level for a given zone or conduit
π Related Concepts
π References
π Prerequisites
Understand these before this topic
π Engineering Applications
See how this applies across industries