← Home

IEC 62443-3-1 Clause 8.2 – Virus and Malicious Code Detection

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 8.2
Related: Clause 8 | SR 3.2 Malicious code protection | 2-1 Component Security | System Hardening | 8.3 IDS

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 8 pages: Cl. 8 | 8.1 Log auditing | 8.2 Malicious code | 8.3 IDS | 8.4 Vulnerability scanners | 8.5 Forensics | 8.6 Host configuration | 8.7 Software management


What it is

Virus detection systems (VDS) in the TR are host or network scanners that look for malicious code. Teaching note: application allowlisting and endpoint detection and response (EDR) matured after 2007 and are often stronger in OT than signature-only antivirus; evaluate them against SR 3.2, not marketing labels. The TR’s coordination and change-control directives still apply.


Vulnerabilities addressed

Malware arriving on removable media, engineering laptops, email or infected servers — ransomware, worms and Trojans that alter logic or encrypt workstations.


Typical deployment

Managed agents on Windows servers and workstations; scanning at zone entry/exit when agents cannot run on controllers or locked HMIs; signature or engine updates from a controlled internal source, not the public internet.


Known issues and weaknesses


Use in IACS

Use vendor-supported modes only. Coordinate VDS policy with IDS and firewalls so each layer has a defined job.


Recommendations