← Home

IEC 62443-3-1 Clause 5 – Authentication and Authorisation

Authorisation decides who and what may enter or leave a system. Authentication proves that the person, device or process requesting access is who they claim to be. They are distinct: authorisation depends on authentication. Together they are the first access-control layer in an IACS.

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 5. Informational, not a requirements standard. Normative identification and use-control requirements are in 3-3 FR 1 and FR 2, and in 2-1 Clause 11.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 5
Related: IEC 62443-3-1 overview | FR 1 Identification and Authentication | FR 2 Use Control | IEC 62443-2-1 Clause 11 | IEC 62443-4-2 Clause 5 | Multi-Factor Authentication (MFA) | Active Directory | PKI

Technology categories: Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10


Authentication factors

Authenticity can be tested with one or more of: something known (password, PIN), something owned (key, dongle, smart card), something physical (fingerprint, retina), a location (GPS or site signature), or the time of the request. More independent factors make a stronger process. Two or more is multi-factor authentication (MFA).

There are two components:


IACS cautions


Technologies in this clause