← Home

IEC 62443-3-1 Clause 7 – Encryption Technologies and Data Validation

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 7
Related: IEC 62443-3-1 overview | FR 4 Data Confidentiality | 2-1 Protection of Data | PKI

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 7 pages: Cl. 7 | 7.1 Symmetric key | 7.2 Public key | 7.3 VPN


Purpose

Encryption conceals meaning (confidentiality) and, with integrity checks and digital signatures, supports data validation and message authentication. That is why message authentication is treated here, not under Clause 5.

In IACS, availability and integrity usually outrank confidentiality. Cryptography adds latency. Match algorithm, key length and placement to process dynamics and asset value; do not encrypt traffic that safety or monitoring must see in the clear unless an equivalent independent path exists.


Technologies in this clause