ics-ottrade-pressNewsThe Broadside2 min read

OT coalition urges ISA/IEC 62443 as unified ICS standard

CIRCIA's harmonization exception lets entities skip duplicate reporting, but without a shared OT baseline to measure "substantially similar" against, the exception can't deliver what it promises.


TL;DR

The Operational Technology Cybersecurity Coalition released a July 23 position paper urging federal policymakers to adopt ISA/IEC 62443 as a single horizontal standard for industrial control system security. Operators currently navigate overlapping mandates (the paper cites TSA pipeline security directives and NERC Critical Infrastructure Protection standards as examples) with no shared technical baseline across sectors. Coalition executive director Tatyana Bolton told Inside Cybersecurity that CIRCIA's proposed harmonization exception, which lets entities skip duplicate reporting under a "substantially similar" framework, can't function cleanly for OT until regulators agree on a common standard to measure similarity against.

The Operational Technology Cybersecurity Coalition's position paper, released July 23, argues that critical infrastructure operators are navigating a "growing patchwork of overlapping cybersecurity rules" and that ISA/IEC 62443 (a set of standards tailored for industrial automation and control systems, adopted by the International Society of Automation and the International Electrotechnical Commission in 2010) should serve as the common technical baseline. The paper's release coincides with two federal developments: a Government Accountability Office report published July 21 that outlined duplicative cyber regulatory requirements across critical infrastructure sectors, and CISA's anticipated September finalization of incident reporting rules under the Cyber Incident Reporting for Critical Infrastructure Act.

The paper highlights the Transportation Security Administration's pipeline security directives and the North American Electric Reliability Corporation's Critical Infrastructure Protection standards as examples of regulations that impose duplicative requirements on the same operators. The GAO report, requested by Homeland Security lawmakers, documented similar fragmentation. The President's National Security Telecommunications Advisory Committee flagged in a 2023 report that proliferating cybersecurity requirements and assurance programs divert resources, and recommended establishing a government office with a primary mission of driving regulatory harmonization. CIRCIA itself directs CISA to harmonize its new reporting regime against other federal requirements.

OTCC proposes what it calls a "better together" approach: pairing ISA/IEC 62443's technical benchmarks with NIST's OT security guidance to satisfy regulatory audit requirements while addressing the engineering realities of operational environments. NIST is currently updating Special Publication 800-82 to expand its scope. The paper also argues that the international standard can accommodate emerging technologies such as artificial intelligence and post-quantum cryptography without requiring entirely new regulatory frameworks.

Bolton told Inside Cybersecurity that CIRCIA's proposed harmonization exception is "the right instinct" but can't function cleanly without a shared baseline. "For OT, there isn't one yet, which is exactly the gap our paper is pointing at," she said, describing CIRCIA's finalization as "a meaningful first step" and ISA/IEC 62443 as "a durable baseline" that would prevent harmonization from becoming "a one-time fix." The paper's recommendations include mandating the standard for government facilities to drive economies of scale for secure components and funding professional certification programs for the OT workforce.


Published ·Deep Fathom

OT coalition urges ISA/IEC 62443 as unified ICS standard — The Broadside