Courseiva

CRISC Information Technology and Security Practice Question

An organization is implementing IEC 62443 for its industrial control systems. Which THREE of the following are key requirements of IEC 62443? (Select three.)

⚠ Common exam trap

CRISC often tests the misconception that IEC 62443 mandates proprietary or single-vendor solutions, when in fact it is a risk-based, multi-vendor standard centered on zones, conduits, security levels, and secure development.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Applying security levels (SL) to each zone based on risk

Option A is correct because IEC 62443 requires assigning Security Levels (SL 1–4) to each zone and conduit based on the assessed risk, so that target security levels can be defined and verified for the assets within them. Option B is correct because IEC 62443-4-1 specifies secure development lifecycle (SDL) requirements for product suppliers, including practices such as threat modeling, secure coding, and vulnerability handling for industrial components. Option D is correct because the standard mandates a risk assessment as the foundation for identifying zones and conduits, which are then used to segment the ICS network and apply appropriate countermeasures. Option C is incorrect because IEC 62443 promotes open, standards-based and interoperable protocols rather than proprietary ones, which can hinder security monitoring and integration. Option E is incorrect because the standard favors defense-in-depth and segmentation across multiple vendors and layers, not single-vendor lock-in, which does not by itself reduce risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Applying security levels (SL) to each zone based on risk

    Why this is correct

    IEC 62443 requires segmentation into zones and conduits, with each zone assigned a target security level derived from assessed risk. This risk-based SL assignment is a foundational requirement, directly matching the stem's option and governing the countermeasures each zone must implement.

  • ✓

    Ensuring all industrial components have a secure development lifecycle (SDL)

    Why this is correct

    IEC 62443-4-1 mandates a secure development lifecycle for product suppliers, ensuring industrial components are built with security baked in. This satisfies the requirement that all components meet defined security levels through documented, auditable development practises.

  • ✗

    Using proprietary protocols to enhance performance

    Why it's wrong here

    IEC 62443 requires open, interoperable standards and segmented zones; proprietary protocols undermine the multi-vendor security and interoperability the standard mandates. It tempts because proprietary protocols can optimise deterministic performance in legacy control networks, but that is an operational choice, not a 62443 requirement.

  • ✓

    Conducting a risk assessment to identify security zones and conduits

    Why this is correct

    IEC 62443 requires zone and conduit segmentation, so a risk assessment identifying those boundaries is foundational. It satisfies the standard's mandate to group assets by risk and define controlled communication paths between zones, directly shaping the security architecture for industrial control systems.

  • ✗

    Implementing a single-vendor solution to reduce complexity

    Why it's wrong here

    IEC 62443 requires zones and conduits, security levels per zone, and defence-in-depth across components; mandating one vendor contradicts its multi-vendor, segmented architecture. It is tempting because single-vendor stacks appear to simplify patching and accountability, which suits some proprietary environments, but the standard deliberately assumes heterogeneous, interoperable systems.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.