← Home

IEC 62443-3-1 Clause 9.3 – Web Technologies

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 9.3
Related: Clause 9 | 6.1 Network firewalls | Network Segmentation | 7.3 VPN

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 9 pages: Cl. 9 | 9.1 Server/workstation OS | 9.2 Real-time/embedded OS | 9.3 Web technologies


What it is

HTTP/HTTPS, browsers, and web-mobile content (the TR names Java/ActiveX-class technologies) used for HMI, diagnostics, historians and remote views. Adding web paths is how many IACS left isolation.


Vulnerabilities addressed

Web connectivity itself is the vulnerability class: browser exploits, unsafe ActiveX/Java, and a path from the internet or enterprise into the process network.


Typical deployment

Web HMI, vendor remote-support portals, embedded web servers on switches and UPSs. Often enabled by default and forgotten.


Known issues and weaknesses

The most secure web posture is no web path into the IACS. Connections save time; they also create a channel that isolation used to deny.


Use in IACS

Small systems, and any system without a substantial benefit from interconnection, are best left stand-alone. If connected, treat the web service as untrusted and gate it.


Recommendations