← Home

IEC 62443-3-1 Clause 5.7 – Location-Based Authentication

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 5.7
Related: Clause 5 | 10.1 Physical protection | MFA

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 5 pages: Cl. 5 | 5.1 RBAC | 5.2 Password | 5.3 Challenge/response | 5.4 Token | 5.5 Smart card | 5.6 Biometric | 5.7 Location | 5.8 Password management | 5.9 Device-to-device


What it is

Authentication that includes where the request comes from: GPS, a location signature sensor, or a known network/site context (for example, engineering actions only from the control room).


Vulnerabilities addressed

Remote sessions that look like a legitimate user but originate off-site. Complements, rather than replaces, something-you-know and something-you-have.


Typical deployment

Policy engines that allow a privileged action only from an approved geofence, subnet or room. Rare as a sole factor.


Known issues and weaknesses

GPS spoofing, poor indoor GPS, and the ease of claiming a false network location. The TR found few industrial references even in 2007.


Use in IACS

Keep recommendations conservative. Location is a supplementary factor for high-privilege remote or roaming access, not a plant-wide authenticator.


Recommendations