IEC 62443 Implementation & Audit Handbook by Kai London
IEC 62443 is the right standard and a hard read. This handbook does the translation — from the parts and roles down to the zone diagram, the target security levels, the control decisions and the evidence file that makes an audit a formality rather than an ordeal.
Available on Amazon.
What is inside
The standard, mapped
How the parts fit together and which ones apply to an asset owner, an integrator and a product supplier.
Zones and conduits in practice
Drawing the partition for a real plant, including the awkward systems that refuse to sit neatly in one zone.
Risk assessment and security levels
Working from consequence to target security level, and documenting the reasoning behind each SL-T.
Control selection and gap closure
Turning foundational requirements into a costed remediation plan with owners and dates.
The evidence file
What to keep, in what form, so a control can be shown to have been operating rather than merely defined.
Audit readiness
How assessments run, the questions that catch programmes out, and how to prepare the people as well as the paperwork.
Who it is for: OT security leads running a 62443 programme, control system engineers and integrators, internal and external auditors, and compliance teams facing NIS2 or sector regulation.
A zone diagram nobody maintains is not a control. It is a drawing.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.