IEC/TR 62443-3-1 (published from ISA-TR99.00.01-2007) is a catalogue of security technologies that may be applied to Industrial Automation and Control Systems (IACS). It is a technical report: it assesses tools and countermeasures, it does not set security levels or system requirements. Those shalls sit in later normative parts, especially 2-1, 3-3 and 4-2.
Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clauses 1–4
Related:
ISA/IEC 62443 series
|
IEC 62443-3-3 Foundational Requirements
|
Defence in Depth
Technology categories: Cl. 5 Authentication | Cl. 6 Filtering | Cl. 7 Encryption | Cl. 8 Monitoring | Cl. 9 Software | Cl. 10 Physical
The report assesses cyber security tools, countermeasures and technologies that may apply to modern electronic IACSs. IACS is used in the broadest sense: DCS, PLC, SCADA, historians, networked sensing, diagnostics, and the industrial network plus related IT devices (firewalls, servers, routers, switches, gateways, fieldbus, IDS, IEDs, RTUs, wired and wireless modems) and the human, network and machine interfaces used to operate them.
Technology categories in the report:
The report categorises technologies then available so later ISA99 / IEC 62443 documents share a common vocabulary. Each technology is discussed in terms of:
Directive: use the report to decide what can reasonably be deployed today and where more work is needed. It does not rank one product class above another. Selection and deployment for a given system remain the asset owner’s responsibility, applied by people who know that control system.
IACS networks moved from isolated, proprietary systems to standards-based networks connected to the enterprise, partners and often the internet. Joint ventures, outsourcing and remote access improved operations and also increased who can reach the control system, and when.
A breach is not only a confidentiality event. Loss of production, environmental harm, regulatory violation or compromise of operational safety can exceed the impact of stolen information, and may extend beyond the plant to regional infrastructure.
Directives:
The TR’s glossary is drawn from FIPS, RFC 2828 and related sources. The terms below are the subset that the rest of these pages rely on. The full glossary is not reproduced.
| Term | Meaning in this report |
|---|---|
| Authentication | Establishing that a person, device, transmission or message is what it claims to be. |
| Authorisation | A right or permission granted to a system entity to access a resource. Proper authorisation depends on authentication. |
| Availability | The chance that an asset can fulfil its required function over a stated period, under reliability, maintainability and security. Usually a higher IACS objective than confidentiality. |
| Confidentiality | Assurance that information is not disclosed to unauthorised individuals, processes or devices. |
| Integrity | Logical correctness of the system and protection against unauthorised modification or destruction of information. |
| Defence in depth | A layered architecture on the assumption that any one control will eventually be defeated. See Defence in Depth. |
| Latency | Time from send to receive. Together with jitter it defines control-loop performance; added security processing must not violate process dynamics. |
| Man-in-the-middle | An attacker intercepts and may modify traffic while masquerading as a legitimate party — including presenting a false-healthy HMI while the process is attacked. |
| RBAC | Role-based access control: permissions attached to roles, people attached to roles. |
| VLAN / VPN | Virtual LAN: logical segmentation of a switched network. Virtual private network: an encrypted tunnel across an untrusted network. |
Each technology child page follows the TR’s assessment skeleton. Category pages (Clauses 5–10) give the section introduction only. Cross-links point to the later normative parts that turn these technologies into requirements.