← Home

IEC 62443-3-1 Clause 10.1 – Physical Protection

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 10.1
Related: Clause 10 | Defence in Depth | 5.4 Physical/token authentication | Network Segmentation

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 10 pages: Cl. 10 | 10.1 Physical protection | 10.2 Personnel security


What it is

Physical protection is layered barriers from the site perimeter to the cabinet and port: fencing, locks, guards, cabinets, port blockers and control of spare media. Barriers must be tailored to the threat (vehicle, explosion, theft, walk-up).


Vulnerabilities addressed

Theft of hosts, insertion of malware via USB, tapping of copper, and any attack that starts by opening a door. Network authentication is bypassed if the attacker has the console.


Typical deployment

Concentric layers: site fence, building access, control-room access, cabinet locks, then disabled unused USB and console ports. Monitoring of perimeters for penetration and tamper patterns.


Known issues and weaknesses

Vegetation and clutter create hiding places. Perimeters that are never walked are theatre. Over-locking can conflict with safety access. Tailoring is site-specific; a generic checklist is not a design.


Use in IACS

Essential for every cyber control that assumes the hardware is still the plant’s hardware.


Recommendations