OT, ICS & SCADA field guides · Standards

IEC 62443 Implementation & Audit Handbook by Kai London

IEC 62443 is the right standard and a hard read. This handbook does the translation — from the parts and roles down to the zone diagram, the target security levels, the control decisions and the evidence file that makes an audit a formality rather than an ordeal.

Available on Amazon.

What is inside

The standard, mapped

How the parts fit together and which ones apply to an asset owner, an integrator and a product supplier.

Zones and conduits in practice

Drawing the partition for a real plant, including the awkward systems that refuse to sit neatly in one zone.

Risk assessment and security levels

Working from consequence to target security level, and documenting the reasoning behind each SL-T.

Control selection and gap closure

Turning foundational requirements into a costed remediation plan with owners and dates.

The evidence file

What to keep, in what form, so a control can be shown to have been operating rather than merely defined.

Audit readiness

How assessments run, the questions that catch programmes out, and how to prepare the people as well as the paperwork.

Who it is for: OT security leads running a 62443 programme, control system engineers and integrators, internal and external auditors, and compliance teams facing NIS2 or sector regulation.

IEC 62443NIS2NIST SP 800-82ISO/IEC 27001Purdue model

A zone diagram nobody maintains is not a control. It is a drawing.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.