← Home

IEC 62443-3-1 Clause 8.5 – Forensics and Analysis Tools (FAT)

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 8.5
Related: Clause 8 | Incident Response and Recovery | Packet Capture Analysis (PCAP) | 8.3 IDS | 2-1 SPE 7

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 8 pages: Cl. 8 | 8.1 Log auditing | 8.2 Malicious code | 8.3 IDS | 8.4 Vulnerability scanners | 8.5 Forensics | 8.6 Host configuration | 8.7 Software management


What it is

Forensics and analysis tools (FAT) capture and reconstruct incidents: what happened, which systems were touched, and in what order. Packet capture is a technique (see PCAP), not a separate 3-1 heading.


Vulnerabilities addressed

Inability to learn from an incident or to support investigation. FAT does not prevent the incident.


Typical deployment

Deploy in tandem with IDS. The threat picture used to tune IDS is a subset of what FAT must be able to reconstruct. Capture points, retention and reduction must be designed, not improvised after the breach.


Known issues and weaknesses

The hard decisions are trade-offs: how much data, from where, how long it persists, and how it is reduced so analysts can use it. Capture that saturates a control link causes a new incident.


Use in IACS

Plan FAT with a threat assessment. Volatile historian and alarm data may overwrite quickly; OT forensics is not a copy of enterprise disk imaging alone.


Recommendations