← Home

IEC 62443-3-1 Clause 8.3 – Intrusion Detection Systems

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 8.3
Related: Clause 8 | Intrusion Prevention Systems | Detection in Depth | FR 6 | 8.1 Log auditing

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 8 pages: Cl. 8 | 8.1 Log auditing | 8.2 Malicious code | 8.3 IDS | 8.4 Vulnerability scanners | 8.5 Forensics | 8.6 Host configuration | 8.7 Software management


What it is

An intrusion detection system (IDS) monitors network (NIDS) or host (HIDS) activity for misuse or anomaly and generates alerts. It does not normally block traffic. Blocking products are intrusion prevention systems (IPS) — not a 3-1 table-of-contents item; treat them as a later technology with a higher availability risk on process traffic.


Vulnerabilities addressed

Attacks and policy violations that have already passed prevention controls. IDS is the alarm, not the lock.


Typical deployment

Span or TAP on a conduit; host agents on servers. Tune signatures and baselines to industrial protocols or expect a flood of false positives.


Known issues and weaknesses


Use in IACS

Fit for IACS when first deployed in detect-only mode. Teaching note: industrial protocol-aware IDS is now available; the TR’s “no automated response until accuracy is trusted” rule is unchanged.


Recommendations