Glossary · OT cybersecurity
Target security level (SL-T)
Also known as: SL-T, Security level target
German: Security Level
In IEC 62443, the target security level (SL-T) is the security level that the asset owner determines, as a result of the security risk assessment, to be required for a zone or conduit. It is compared with the capability security level (SL-C) of the chosen components and the achieved security level (SL-A) of the implemented system.
- OT security
- Standards
In one sentence
In IEC 62443, the target security level (SL-T) is the security level required for a zone or conduit, set by the security risk assessment.
Example
The risk assessment sets SL-T 2 for the packaging zone; the integrator selects components with SL-C 2 and later verifies that the installed zone achieves SL-A 2.
How it applies
- Engineering: IEC 62443-3-2 derives SL-T per zone and conduit. The SL-T can be stated per foundational requirement as a vector, for example high for integrity and low for confidentiality.
- Procurement: The SL-T feeds into requirements for suppliers: components should offer at least the required capability (SL-C) under IEC 62443-4-2, or compensating measures must close the gap.
- Verification: The achieved level (SL-A) is assessed on the implemented system. If SL-A is below SL-T, the gap must be treated as a risk.
- Documentation: Security requirement specifications should state SL-T per zone and conduit. Product documentation should state the SL-C the product supports and under which conditions, such as required settings or compensating measures in the environment.
SL-T vs. SL-C vs. SL-A
SL-T is what is required, SL-C is what a component can provide when properly configured, and SL-A is what the implemented system actually achieves. Confusing them in documents leads to false claims of security.