GSO IEC 62443-2-1:2025
IEC 62443-2-1:2024
Gulf Standard
Current Edition
·
Approved on
14 October 2025
Security for industrial automation and control systems - Part 2-1: Security program requirements for IACS asset owners
GSO IEC 62443-2-1:2025 Files
English
189 Pages
Current Edition
Reference Language
Obtaining this standard through the store is currently unavailable. You can acquire it directly from its source.
GSO IEC 62443-2-1:2025 Scope
IEC 62443-2-1:2024 specifies asset owner security program (SP) policy and procedure requirements for an industrial automation and control system (IACS) in operation. This document uses the broad definition and scope of what constitutes an IACS as described in IEC TS 62443‑1‑1. In the context of this document, asset owner also includes the operator of the IACS.
This document recognizes that the lifespan of an IACS can exceed twenty years, and that many legacy systems contain hardware and software that are no longer supported. Therefore, the SP for most legacy systems addresses only a subset of the requirements defined in this document. For example, if IACS or component software is no longer supported, security patching requirements cannot be met. Similarly, backup software for many older systems is not available for all components of the IACS. This document does not specify that an IACS has these technical requirements. This document states that the asset owner needs to have policies and procedures around these types of requirements. In the case where an asset owner has legacy systems that do not have the native technical capabilities, compensating security measures can be part of the policies and procedures specified in this document.
This edition includes the following significant technical changes with respect to the previous edition:
a) revised requirement structure into SP elements (SPEs),
b) revised requirements to eliminate duplication of an information security management system (ISMS), and
c) defined a maturity model for evaluating requirements.
This document recognizes that the lifespan of an IACS can exceed twenty years, and that many legacy systems contain hardware and software that are no longer supported. Therefore, the SP for most legacy systems addresses only a subset of the requirements defined in this document. For example, if IACS or component software is no longer supported, security patching requirements cannot be met. Similarly, backup software for many older systems is not available for all components of the IACS. This document does not specify that an IACS has these technical requirements. This document states that the asset owner needs to have policies and procedures around these types of requirements. In the case where an asset owner has legacy systems that do not have the native technical capabilities, compensating security measures can be part of the policies and procedures specified in this document.
This edition includes the following significant technical changes with respect to the previous edition:
a) revised requirement structure into SP elements (SPEs),
b) revised requirements to eliminate duplication of an information security management system (ISMS), and
c) defined a maturity model for evaluating requirements.
Best Sellers From Electrical Sector
GSO 2530:2016
Gulf Standard
Energy Labelling And Minimum Energy Performance Requirements For Air-Conditioners

GSO 34:2007
Gulf Technical Regulation
LEAD-ACID STARTER BATTERIES USED FOR
MOTOR VEHICLES AND INTERNAL
COMBUSTION ENGINES

BH GSO 34:2015
GSO 34:2007
Bahraini Technical Regulation
LEAD-ACID STARTER BATTERIES USED FOR
MOTOR VEHICLES AND INTERNAL
COMBUSTION ENGINES


GSO 35:2007
Gulf Standard
Methods of test
for lead-acid starter batteries used for motor vehicles
and internal combustion engines

Recently Published from Electrical Sector
GSO IEC 62973-3:2025
IEC 62973-3:2024
Gulf Standard
Railway applications - Rolling stock - Batteries for auxiliary power supply systems - Part 3: Lead acid batteries


GSO IEC 62680-1-2:2025
IEC 62680-1-2:2024
Gulf Standard
Universal serial bus interfaces for data and power - Part 1-2: Common components - USB Power Delivery specification


GSO IEC 60704-2-9:2025
IEC 60704-2-9:2024
Gulf Standard
Household and similar electrical appliances - Test code for the determination of airborne acoustical noise - Part 2-9: Particular requirements for electric hair care appliances


GSO IEC 61969-3:2025
IEC 61969-3:2023
Gulf Standard
Mechanical structures for electrical and electronic equipment - Outdoor enclosures - Part 3: Environmental requirements, tests and safety aspects

