ISA/IEC 62443-2-1 defines SP Element 1 – Organizational Security Measures as the set of governance, policy, and people-focused controls that establish the foundation of an IACS Security Program. These measures are organizational in nature and are intended to create accountability, awareness, and structured risk management.
Step 1: Scope of SP Element 1
SP Element 1 includes activities such as:
Security policy definition
Roles and responsibilities
Personnel security (e.g., background checks)
Security awareness and training
Supply chain security governance
These controls ensure that people, processes, and third-party relationships support cybersecurity objectives.
Step 2: Why malware protection does not belong here
Malware protection is a technical control, not an organizational measure. In ISA/IEC 62443, malware protection is addressed under SP Element 4 – Component Hardening, which focuses on endpoint protection, anti-malware mechanisms, and secure configurations.
Step 3: Why the other options are valid
Background checks are explicitly part of personnel security.
Supply chain security is a key organizational concern.
Security awareness training ensures staff understand their responsibilities.
Therefore, Malware protection is not listed under SP Element 1.