← Home

IEC 62443-3-1 Clause 8.1 – Log Auditing Utilities

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 8.1
Related: Clause 8 | Detection in Depth | 2-1 SPE 7 | FR 6 | Packet Capture Analysis (PCAP)

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 8 pages: Cl. 8 | 8.1 Log auditing | 8.2 Malicious code | 8.3 IDS | 8.4 Vulnerability scanners | 8.5 Forensics | 8.6 Host configuration | 8.7 Software management


What it is

Log auditing utilities collect, retain and review records of system and security events. Active log management can flag an attack or policy violation in progress and help locate it. Teaching note: a SIEM (Security Information and Event Management) platform is the usual modern aggregator for these functions; the TR describes the capability, not the product class.


Vulnerabilities addressed

Undetected misuse, lack of accountability, and inability to reconstruct an incident. Logs are evidence of integrity as well as of intrusion.


Typical deployment

Host and application logs, firewall and authentication logs, forwarded to a collector with time synchronisation. Review may be manual, scheduled or correlated.


Known issues and weaknesses


Use in IACS

Plan logging at project inception, or retrofit promptly. There is enough value in a tangible integrity record to warrant use even on plants that will not staff a 24-hour SOC.


Recommendations