Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 5.7
Related:
Clause 5
|
10.1 Physical protection
|
MFA
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 5 pages: Cl. 5 | 5.1 RBAC | 5.2 Password | 5.3 Challenge/response | 5.4 Token | 5.5 Smart card | 5.6 Biometric | 5.7 Location | 5.8 Password management | 5.9 Device-to-device
Authentication that includes where the request comes from: GPS, a location signature sensor, or a known network/site context (for example, engineering actions only from the control room).
Remote sessions that look like a legitimate user but originate off-site. Complements, rather than replaces, something-you-know and something-you-have.
Policy engines that allow a privileged action only from an approved geofence, subnet or room. Rare as a sole factor.
GPS spoofing, poor indoor GPS, and the ease of claiming a false network location. The TR found few industrial references even in 2007.
Keep recommendations conservative. Location is a supplementary factor for high-privilege remote or roaming access, not a plant-wide authenticator.