← Home

IEC 62443-3-1 Clause 5.6 – Biometric Authentication

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 5.6
Related: Clause 5 | MFA | Clause 4 essential functions

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 5 pages: Cl. 5 | 5.1 RBAC | 5.2 Password | 5.3 Challenge/response | 5.4 Token | 5.5 Smart card | 5.6 Biometric | 5.7 Location | 5.8 Password management | 5.9 Device-to-device


What it is

Something you are: fingerprint, iris, face, voice or similar biological characteristic used as an authenticator.


Vulnerabilities addressed

Shared or written-down passwords; some forms of token lending. Biometrics bind the person more tightly than a card that can be handed over.


Typical deployment

Usually a second factor at a door or a workstation, not the only factor. Sensors must be installed where people actually work.


Known issues and weaknesses

Plant environment is the TR’s main warning: dirt, gloves, moisture, lighting, injury and outdoor cabinets all raise false reject and false accept rates. Office datasheets do not predict field performance. Privacy and fallback access also matter.


Use in IACS

Valuable if the installation environment is qualified with the vendor. Unreliable if dropped onto a dusty outdoor HMI without that work.


Recommendations