← Home

IEC 62443-3-1 Clause 6.2 – Host-Based Firewalls

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 6.2
Related: Clause 6 | 6.1 Network firewalls | System Hardening | 2-1 Component Security

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 6 pages: Cl. 6 | 6.1 Network firewalls | 6.2 Host firewalls | 6.3 Virtual networks


What it is

A host-based firewall is software on a workstation or server that filters that host’s traffic. It is not a substitute for a network firewall at a zone boundary.


Vulnerabilities addressed

Unauthorised inbound services on a single host, and some lateral movement if the host is compromised less completely than the network around it.


Typical deployment

OS firewalls on Windows or Unix engineering stations and servers. Rare on controllers.


Known issues and weaknesses


Use in IACS

Few host-based firewalls in genuine control environments. Prefer network firewalls and industrial protocol-aware filters at the zone edge. Teaching note: some modern OT hosts ship a vendor-supported host filter; still require written approval before adding third-party software.


Recommendations