Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 10.1
Related:
Clause 10
|
Defence in Depth
|
5.4 Physical/token authentication
|
Network Segmentation
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 10 pages: Cl. 10 | 10.1 Physical protection | 10.2 Personnel security
Physical protection is layered barriers from the site perimeter to the cabinet and port: fencing, locks, guards, cabinets, port blockers and control of spare media. Barriers must be tailored to the threat (vehicle, explosion, theft, walk-up).
Theft of hosts, insertion of malware via USB, tapping of copper, and any attack that starts by opening a door. Network authentication is bypassed if the attacker has the console.
Concentric layers: site fence, building access, control-room access, cabinet locks, then disabled unused USB and console ports. Monitoring of perimeters for penetration and tamper patterns.
Vegetation and clutter create hiding places. Perimeters that are never walked are theatre. Over-locking can conflict with safety access. Tailoring is site-specific; a generic checklist is not a design.
Essential for every cyber control that assumes the hardware is still the plant’s hardware.