Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 7
Related:
IEC 62443-3-1 overview
|
FR 4 Data Confidentiality
|
2-1 Protection of Data
|
PKI
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 7 pages: Cl. 7 | 7.1 Symmetric key | 7.2 Public key | 7.3 VPN
Encryption conceals meaning (confidentiality) and, with integrity checks and digital signatures, supports data validation and message authentication. That is why message authentication is treated here, not under Clause 5.
In IACS, availability and integrity usually outrank confidentiality. Cryptography adds latency. Match algorithm, key length and placement to process dynamics and asset value; do not encrypt traffic that safety or monitoring must see in the clear unless an equivalent independent path exists.