Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 9.3
Related:
Clause 9
|
6.1 Network firewalls
|
Network Segmentation
|
7.3 VPN
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 9 pages: Cl. 9 | 9.1 Server/workstation OS | 9.2 Real-time/embedded OS | 9.3 Web technologies
HTTP/HTTPS, browsers, and web-mobile content (the TR names Java/ActiveX-class technologies) used for HMI, diagnostics, historians and remote views. Adding web paths is how many IACS left isolation.
Web connectivity itself is the vulnerability class: browser exploits, unsafe ActiveX/Java, and a path from the internet or enterprise into the process network.
Web HMI, vendor remote-support portals, embedded web servers on switches and UPSs. Often enabled by default and forgotten.
The most secure web posture is no web path into the IACS. Connections save time; they also create a channel that isolation used to deny.
Small systems, and any system without a substantial benefit from interconnection, are best left stand-alone. If connected, treat the web service as untrusted and gate it.