IEC 62443, Governance, Compliance and Board by Kai London
Industrial operators now answer to more than one regulator, several standards and a supply chain that asks its own questions. Volume 3 turns that overlapping demand into a single governance system — one set of controls, one evidence base, and a board report that says something.
Available on Amazon.
What is inside
IEC 62443 as a governance spine
Using the standard as the organising structure that the other obligations map onto.
NIS2 and the Cyber Resilience Act
Scope, duties, incident reporting and product obligations for operators and manufacturers alike.
NERC CIP and sector regimes
Where prescriptive regulation differs from risk-based standards, and how to satisfy both without duplicating work.
Supplier and product risk
Assessing OEMs and integrators, security requirements in procurement, and evidence of product security claims.
Audit evidence
What to collect, where it lives, and how to show a control was operating across a reporting period.
Executive and board reporting
Industrial cyber risk expressed as consequence to operations, with the assurance behind each statement.
Who it is for: OT governance and compliance leads, internal and external auditors, procurement and supplier assurance, and the executives and directors of industrial and infrastructure operators.
One control set, one evidence base, many regulators. Anything else is a compliance treadmill.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.