ACSSADeep diveExplainer

IEC 62443 zone sampling in an ACSSA assessment: how zones, conduits and systems are sampled at maturity level 3

Where ISASecure ACSSA samples zones, device-bearing conduits and systems at maturity level 3, how the evaluator chooses the sample, and what to have ready.

Perseus ISASecure Assessor TeamSeptember 8, 20268 min read

Asset owners new to ISASecure ACSSA ask two questions about sampling in one breath: "Will the evaluator look at every zone?" and "How many zones will they pick?" The honest answers are "not necessarily" and "none of the ACSSA documents held gives a number". Both deserve unpacking: the rules are more structured than a percentage, and the inputs are largely yours.

Sampling happens only at maturity level 3

For certification, ACSSA judges each security-program and risk-assessment requirement at two maturity levels: level 2 asks whether policies and procedures are documented, level 3 whether they are practised for this IACS (level 1 exists only in the inspection scheme). Nothing at level 2 is sampled. Those results are recorded IACS-wide (risk assessment), per policy-governed part of the IACS (security program) or per service provider.

Sampling enters at level 3, where "is it done here" needs a specific zone, conduit or system. ACSSA-300's Table 1 names the entity each level 3 result is recorded against; some rows are scored on a sample, the rest as a census.

How the 419 evaluatable methods are scored at maturity level 3: sampled or census

Zone and device-bearing-conduit sampling carries most of the evaluation; service-provider requirements are never sampled. Derived from ACSSA-300 v1.5 Table 1 row membership and ACSSA-311 v1.3 counts.

The 419 figure is derived from the ACSSA-311 workbook: three of its 422 rows are grouping headers with no result of their own. Set against Table 1:

  • 269 methods per sampled zone or device-bearing conduit: the 143 IEC 62443-2-1 and support-item methods that are not IACS-wide, all 111 evaluatable IEC 62443-3-3 capability methods, and 15 risk-assessment methods (the 14 under ZCR 5 plus ZCR 6.4).
  • 13 methods per sampled system under consideration: the six ZCR 3 items and the seven ZCR 6 items other than 6.1 and 6.4.
  • 137 methods never sampled: all 123 IEC 62443-2-4 requirements, evaluated for every qualifying service provider; the nine IACS-wide security-program requirements (NET 1.1 to 1.3, ORG 1.1 to 1.5 and ORG 2.4); and five risk-assessment items (ZCR 1, 2, 4, 6.1 and 7) evaluated for every system.

A service provider is therefore never "outside the sample"; a zone left out of it receives no result for the per-zone requirements.

Three levels: system, zone, device-bearing conduit

Your IEC 62443-3-2 work supplies the structure: systems under consideration, typically one per risk assessment, each partitioned into zones and conduits.

  • System under consideration. ZCR 3 and most of ZCR 6. ACSSA-300 aims this level at fleets of replicated systems, substations or wellheads built to one design; for a small, heterogeneous IACS it is not expected; where system sampling is used, the report documents the rationale.
  • Zone. The bulk of the level 3 work: the per-zone security-program requirements, every capability requirement, ZCR 6.4, and the ZCR 5 items, which are sampled within each system whose ZCR 4.1 outcome called for a detailed risk assessment.
  • Device-bearing conduit. A conduit containing devices is evaluated and sampled like a zone; one without devices carries no separate results, since the zones at its ends cover it.

One zone is never optional

For the per-zone security-program requirements and every capability requirement, the sample is drawn across the whole IACS, and ACSSA-300 requires it to include the highest-target-level zone that also has the most technical capabilities, likewise for device-bearing conduits. "Most technical capabilities" is not defined in the documents held, so that half of the choice is evaluator judgement; the mandate itself is a shall.

ACSSA-304 builds Phase 3, the on-site maturity-level-3 evaluation, around it: the IACS-wide organisational requirements first, then every applicable requirement for that zone, then a representative set across a sample of the remaining zones.

How the sample is chosen: five rules

ACSSA-300 contains 37 numbered requirements; five of them, ISASecure_ACS_SZS.R1 to R5, govern sampling. Three are "shall", one is "should", one is "may".

SZS.R1: document the risk properties (shall). For every system under consideration, zone and device-bearing conduit, the evaluator records values for at least the risk properties in ACSSA-300's Table 2: eleven for zones and conduits, ten for systems.

#Zone or device-bearing conduit (11)System under consideration (10)
1Residual risk, given the mitigations in placeWorst-case unmitigated risk
2Residual risk above the system's tolerable levelAny zone or conduit whose residual risk exceeds the tolerable level
3Target security levelHighest target security level in the system
4Safety functions hostedSafety functions hosted
5Other essential functions hostedOther essential functions hosted
6Connection to an untrusted networkConnection to an untrusted network
7Count of connected zones at the same or a lower target level
8Count of network endpointsCount of network endpoints
9Recent change in responsibilityRecent change in responsibility for zones or conduits
10Installation status: established, recently changed or newInstallation status: established, recently changed or new
11Origin of previously identified issuesOrigin of previously identified issues

Almost every value comes from your IEC 62443-3-2 risk assessment, asset inventory or change record; the evaluator collects rather than invents.

SZS.R2: select on risk and diversity (should). A majority of the sampled entities should exceed a threshold the evaluator sets on at least one property. Selection should also seek diversity on five factors: system products and their versions; component types and suppliers; technical and procedural security approaches; the organisations responsible; and membership in the zone groups of your risk assessment. Different requirements may share one sample or use different ones.

SZS.R3: write down the rationale (shall). The evaluator documents how the sample reflects the properties and factors and argues that it meets the sampling objective. In plain terms: if every sampled entity passes, there should be sound grounds to believe that any nonconformity remaining in the unexamined zones, conduits or systems would expose the system concerned to no more risk than it can tolerate. The report carries a summary.

SZS.R4: a second look (shall). The conformity assessment body's own process then checks the inputs and the argument: the recorded property values, the zones, conduits and systems proposed and why they were thought diverse enough, and whether anything could still let the sample miss the objective above. As an ISASecure certification body, Perseus carries out that review before any sample is relied on.

SZS.R5: adjust if needed (may). The sample may be enlarged or changed on new information, notably to find out whether a nonconformity found in one zone is isolated or systemic; at surveillance and recertification that distinction feeds the major-or-minor classification.

Who chooses

ACSSA-304's Phase 3 guidance (informative points on the sampling regime) places the selection with the conformity assessment body, not the asset owner, and expects it to understand the whole population first; random selection is for cases where nothing differentiates the candidates.

Interviews follow roles, not zones

Interviews are mandatory and documented, and the rule (ACSSA-300 R10) is about people, not places. For measures that people carry out, the evaluator interviews at least one representative of each functional role relevant within the sampled zones and conduits, on the asset owner's or a service provider's staff, unless the report justifies a departure. The example roles are operators, maintenance and engineering staff, IT/OT administrators and the security lead; a questionnaire may substitute at the conformity assessment body's discretion. It is not one interview per zone: one operator may cover that role across several sampled zones, and a multi-role zone needs a voice for each.

What passing on the sample means

Certification requires every requirement to pass to level 3. For sampled requirements, ACSSA-300 requires passing on every sampled entity; it states no minimum share of zones, and none of the ACSSA documents held states a sample size, percentage or count. Where an IACS has few zones the sample may be the whole population; sampling earns its keep where zones are numerous and alike.

What the report records

ACSSA-303's report template gives sampling its own section (6.5) with a subsection each for systems, zones and device-bearing conduits; Table 13 holds the zone property values, with parallel tables for systems and conduits where those are sampled, followed by the diversity factors, the sample used per requirement and the rationale. Entities not sampled for a requirement are marked not examined, never "not required for the target security level", a result reserved for capabilities above the zone's target.

What to have ready

  • Property values per zone, conduit and system from the risk assessment: residual and tolerable risk, target level, safety and essential functions, untrusted-network connections, and the highest target level in each system.
  • Inventory counts: network endpoints per zone, and connected zones at the same or a lower target level, from a current asset inventory and the zone-and-conduit drawings.
  • Zone groups, history and diversity: the risk assessment's zone groups; which zones are new, changed or established; where responsibility changed hands or past issues originated; which organisations, products and suppliers each zone involves.
  • A role map of who holds each functional role in each zone that might be sampled.
  • Artifacts for every zone, not only the likely picks: the sample may grow.

Prepared this way, the sample becomes a documented, reviewable choice rather than a negotiation on the day. The series index holds the rest of the ACSSA articles. For the contrast, SSA certifies a supplier's system as sold rather than an installed one and samples nothing; ACSSA samples because its object is a live IACS with as many zones as its owner has built.

Frequently asked questions

Not necessarily. Security-program and system-capability requirements at maturity level 3 are scored on a sample of zones and device-bearing conduits, while service-provider requirements, the nine IACS-wide security-program requirements and five risk-assessment items are evaluated in full. ACSSA-300 requires passing on every sampled entity and states no minimum share of zones. One zone is never optional: the highest-target-level zone with the most technical capabilities.

ISASecure ACSSAIEC 62443 zone samplingIEC 62443-3-2 zones and conduitsmaturity level 3ISASecure ACSSA-300asset owner certification
Share this article
Back to Insights

Ready to Get Started?

Let our team of experts help you achieve and maintain compliance with industry-leading cybersecurity standards.