Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 8.3
Related:
Clause 8
|
Intrusion Prevention Systems
|
Detection in Depth
|
FR 6
|
8.1 Log auditing
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 8 pages: Cl. 8 | 8.1 Log auditing | 8.2 Malicious code | 8.3 IDS | 8.4 Vulnerability scanners | 8.5 Forensics | 8.6 Host configuration | 8.7 Software management
An intrusion detection system (IDS) monitors network (NIDS) or host (HIDS) activity for misuse or anomaly and generates alerts. It does not normally block traffic. Blocking products are intrusion prevention systems (IPS) — not a 3-1 table-of-contents item; treat them as a later technology with a higher availability risk on process traffic.
Attacks and policy violations that have already passed prevention controls. IDS is the alarm, not the lock.
Span or TAP on a conduit; host agents on servers. Tune signatures and baselines to industrial protocols or expect a flood of false positives.
Fit for IACS when first deployed in detect-only mode. Teaching note: industrial protocol-aware IDS is now available; the TR’s “no automated response until accuracy is trusted” rule is unchanged.