Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 9.2
Related:
Clause 9
|
4-2 Embedded device requirements
|
4-2 Host device requirements
|
ZCR 3
|
System Hardening
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 9 pages: Cl. 9 | 9.1 Server/workstation OS | 9.2 Real-time/embedded OS | 9.3 Web technologies
Real-time and embedded operating systems (RTOS) on PLC, RTU, IED and similar devices. Patching, agents and host firewalls are often impossible. Security is mostly architecture: isolation, least connectivity, and vendor configuration.
Exposure of time-critical control traffic and management ports to the same network as diagnostics, file transfer or the enterprise. A flooded or scanned embedded stack can miss deadlines even without a “successful” exploit.
Controllers on a dedicated control LAN; engineering and diagnostic access via a conduit with a firewall. Management interfaces not advertised to the enterprise.
TCP/IP on embedded devices increases reachability and attack surface. Many stacks have limited authentication (see 5.9). Firmware updates are slow and vendor-controlled.
Assume the embedded OS cannot run general-purpose security software. Compensate at the zone boundary and with physical protection of cabinets.