BPMN-Based Approach for Modeling IEC 62443 Security Programs for OT Asset Owners
Julia Becker , Simon Jonas Leister , Natalia Moriz und Henning Trsek,The increasingly interconnected information technology and operational technology environments in Industry 4.0 expand the attack surface for cybercrime, thereby contributing to a progressively dynamic cybersecurity threat landscape. To ensure the secure operation of industrial automation and control systems, asset owners are required to implement and maintain a security program in accordance with standards such as IEC 62443. Nevertheless, the implementation of such a security program is often constrained by limited resources, requiring specially trained security experts, significant time, and considerable financial resources. Moreover, while the standards specify which requirements have to be fulfilled, they provide limited guidance on how the corresponding processes should be executed and assigned to organizational roles, making them difficult to understand, especially for non-experts. In this work in progress, we propose a Business Process Model and Notation-based approach for modeling the implementation and maintenance of a security program as defined in IEC 62443. By breaking down the requirements of the standard into structured, role-specific process steps, the model provides comprehensible guidance for responsible personnel and serves as a basis for identifying process steps that can be supported by artificial intelligence. We intend to illustrate the approach using the security program element
“Network and Communication Security”.
| author | = | {Becker, Julia and Leister, Simon Jonas and Moriz, Natalia and Trsek, Henning}, |
| title | = | {BPMN-Based Approach for Modeling IEC 62443 Security Programs for OT Asset Owners}, |
| booktitle | = | {2026 IEEE 31st International Conference on Emerging Technologies and Factory Automation (ETFA)}, |
| year | = | {2026}, |
| editor | = | {}, |
| volume | = | {}, |
| series | = | {}, |
| pages | = | {0}, |
| address | = | {Västerås, Sweden}, |
| month | = | {Sep}, |
| organisation | = | {}, |
| publisher | = | {IEEE}, |
| note | = | {}, |