← Home

IEC 62443-3-1 Clause 6 – Filtering / Blocking / Access Control

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 6
Related: IEC 62443-3-1 overview | FR 5 Restricted Data Flow | Network Segmentation | Firewall Planning and Lifecycle | Network Security Devices

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 6 pages: Cl. 6 | 6.1 Network firewalls | 6.2 Host firewalls | 6.3 Virtual networks


Purpose

Filtering and blocking technologies control what traffic may cross a boundary between networks or hosts. In an IACS they implement zone and conduit policy: deny by default, permit only what the process needs.

The IACS constraint is protocol blindness. Many industrial protocols are not understood by generic IT filters, so a firewall that cannot inspect MODBUS/TCP or EtherNet/IP can only filter on address and port — not on function code or register write.


Technologies in this clause