The international standard for Industrial Automation and Control System (IACS) security explicitly requires incident response testing. Map your exercises to IEC 62443-2-1 Clause 4.3.3, Security Levels 1–4, and the 7 Foundational Requirements — with automated evidence generation built in.
⚠️ This toolkit is an educational resource for exercise program design. Skyhigh Cybersecurity does not provide IEC 62443 certification, formal assessment, or conformity testing services. Engage an accredited certification body for official IEC 62443 certification requirements.
| Standard Part / Clause | Requirement Description | Coverage | Skyhigh Evidence |
|---|---|---|---|
| 2-1§4.3.3 | Incident Response and Recovery Planning — requires periodic testing of IR procedures | Core | Every tabletop exercise IS the §4.3.3 test. Dated AAR + evidence package = audit artifact |
| 2-1§4.2.3 | Risk Assessment — identify and evaluate IACS cybersecurity risks | Supporting | AAR gap analysis maps to risk register; scenario selection validates risk prioritisation methodology |
| 2-1§4.3.4 | Business Continuity Planning — maintain operations during and after cyber events | Direct | BC/DR scenarios test manual operations fallback; recovery timeline evidence for auditors |
| 2-4SP.03.01 | Incident Management for OSSPs / service providers — MSSP-specific incident handling requirements | Direct | MSSP-client exercises using per-client portal; SLA fulfillment evidence via client-agreements module |
| 3-2Security Risk Assessment | Scenario-based risk assessment for IACS zones and conduits | Supporting | Scenario library covers zone-based and conduit threats; MITRE ATT&CK for ICS mapping |
| 3-3FR 6 — Timely Response | IACS shall respond to events in a timely manner (SL 1–4 metric varies) | Core | MTTD/MTTR metrics captured per step; response time evidence against SL-appropriate benchmarks |
| 3-3FR 7 — Resource Availability | IACS shall be available when needed; protection against DoS and resource exhaustion | Direct | Availability and BC/DR scenarios test recovery procedures; downtime impact analysis in AAR |
| 3-3FR 1, FR 2, FR 5 | ID & Auth Control (FR 1); Use Control (FR 2); Restricted Data Flow / Zone Integrity (FR 5) | Supporting | Scenarios test credential abuse (FR 1), privilege escalation (FR 2), and lateral movement across zones (FR 5) |
FR = Foundational Requirement per IEC 62443-3-3. §2-1 refers to IEC 62443-2-1 (Policies & Procedures for Asset Owners).
Skyhigh exercise evidence maps to multiple frameworks simultaneously. One exercise program — complete regulatory coverage.
Launch your first §4.3.3-compliant incident response test in under an hour. Free plan available.