← Home
IEC 62443-3-1 Clause 5 – Authentication and Authorisation
Authorisation decides who and what may enter or leave a system.
Authentication proves that the person, device or process requesting access is
who they claim to be. They are distinct: authorisation depends on authentication. Together they
are the first access-control layer in an IACS.
Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007),
Clause 5. Informational, not a requirements standard. Normative identification and use-control
requirements are in
3-3 FR 1 and
FR 2, and in
2-1 Clause 11.
Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 5
Related:
IEC 62443-3-1 overview
|
FR 1 Identification and Authentication
|
FR 2 Use Control
|
IEC 62443-2-1 Clause 11
|
IEC 62443-4-2 Clause 5
|
Multi-Factor Authentication (MFA)
|
Active Directory
|
PKI
Technology categories:
Cl. 5
|
Cl. 6
|
Cl. 7
|
Cl. 8
|
Cl. 9
|
Cl. 10
Authentication factors
Authenticity can be tested with one or more of: something known (password, PIN), something
owned (key, dongle, smart card), something physical (fingerprint, retina), a location
(GPS or site signature), or the time of the request. More independent factors make a stronger
process. Two or more is
multi-factor authentication (MFA).
There are two components:
- User authentication — logging into a computer or enabling an HMI action.
- Network service authentication — a networked device distinguishing authorised
from unauthorised remote requests. Do not confuse this with message authentication
(integrity of a transmitted message), which belongs in
Clause 7.
IACS cautions
- Many IACS hosts still rely on traditional passwords, including vendor default
passwords that are easy to guess and infrequently changed. Change them.
- Protocols used in IACS often have inadequate or no network-service authentication.
Compensate with zone and conduit controls until the protocol authenticates peers.
See 5.9.
- Authorisation can be as narrow as a file or as wide as an entire plant network. It is
usually configured through vendor OS, application and network tools — and that
diversity is an administrative problem.
Technologies in this clause