← Home

IEC 62443-3-1 Clause 9.2 – Real-Time and Embedded Operating Systems

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 9.2
Related: Clause 9 | 4-2 Embedded device requirements | 4-2 Host device requirements | ZCR 3 | System Hardening

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 9 pages: Cl. 9 | 9.1 Server/workstation OS | 9.2 Real-time/embedded OS | 9.3 Web technologies


What it is

Real-time and embedded operating systems (RTOS) on PLC, RTU, IED and similar devices. Patching, agents and host firewalls are often impossible. Security is mostly architecture: isolation, least connectivity, and vendor configuration.


Vulnerabilities addressed

Exposure of time-critical control traffic and management ports to the same network as diagnostics, file transfer or the enterprise. A flooded or scanned embedded stack can miss deadlines even without a “successful” exploit.


Typical deployment

Controllers on a dedicated control LAN; engineering and diagnostic access via a conduit with a firewall. Management interfaces not advertised to the enterprise.


Known issues and weaknesses

TCP/IP on embedded devices increases reachability and attack surface. Many stacks have limited authentication (see 5.9). Firmware updates are slow and vendor-controlled.


Use in IACS

Assume the embedded OS cannot run general-purpose security software. Compensate at the zone boundary and with physical protection of cabinets.


Recommendations