← Home

IEC 62443-3-1 – Security Technologies for IACS

IEC/TR 62443-3-1 (published from ISA-TR99.00.01-2007) is a catalogue of security technologies that may be applied to Industrial Automation and Control Systems (IACS). It is a technical report: it assesses tools and countermeasures, it does not set security levels or system requirements. Those shalls sit in later normative parts, especially 2-1, 3-3 and 4-2.

Teaching note: These summaries paraphrase IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The report is informational, not a requirements standard. Confirm wording in the published TR. Where 2007 “future directions” are now common practice (for example industrial protocol inspection, TLS, MFA), a short teaching note is added — the TR itself is not rewritten as if it were current.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clauses 1–4
Related: ISA/IEC 62443 series | IEC 62443-3-3 Foundational Requirements | Defence in Depth

Technology categories: Cl. 5 Authentication | Cl. 6 Filtering | Cl. 7 Encryption | Cl. 8 Monitoring | Cl. 9 Software | Cl. 10 Physical


Clause 1 – Scope

The report assesses cyber security tools, countermeasures and technologies that may apply to modern electronic IACSs. IACS is used in the broadest sense: DCS, PLC, SCADA, historians, networked sensing, diagnostics, and the industrial network plus related IT devices (firewalls, servers, routers, switches, gateways, fieldbus, IDS, IEDs, RTUs, wired and wireless modems) and the human, network and machine interfaces used to operate them.

Technology categories in the report:


Clause 2 – Purpose

The report categorises technologies then available so later ISA99 / IEC 62443 documents share a common vocabulary. Each technology is discussed in terms of:

Directive: use the report to decide what can reasonably be deployed today and where more work is needed. It does not rank one product class above another. Selection and deployment for a given system remain the asset owner’s responsibility, applied by people who know that control system.


Clause 4 – Overview

IACS networks moved from isolated, proprietary systems to standards-based networks connected to the enterprise, partners and often the internet. Joint ventures, outsourcing and remote access improved operations and also increased who can reach the control system, and when.

A breach is not only a confidentiality event. Loss of production, environmental harm, regulatory violation or compromise of operational safety can exceed the impact of stolen information, and may extend beyond the plant to regional infrastructure.

Directives:


Clause 3 – Selected definitions

The TR’s glossary is drawn from FIPS, RFC 2828 and related sources. The terms below are the subset that the rest of these pages rely on. The full glossary is not reproduced.

Term Meaning in this report
Authentication Establishing that a person, device, transmission or message is what it claims to be.
Authorisation A right or permission granted to a system entity to access a resource. Proper authorisation depends on authentication.
Availability The chance that an asset can fulfil its required function over a stated period, under reliability, maintainability and security. Usually a higher IACS objective than confidentiality.
Confidentiality Assurance that information is not disclosed to unauthorised individuals, processes or devices.
Integrity Logical correctness of the system and protection against unauthorised modification or destruction of information.
Defence in depth A layered architecture on the assumption that any one control will eventually be defeated. See Defence in Depth.
Latency Time from send to receive. Together with jitter it defines control-loop performance; added security processing must not violate process dynamics.
Man-in-the-middle An attacker intercepts and may modify traffic while masquerading as a legitimate party — including presenting a false-healthy HMI while the process is attacked.
RBAC Role-based access control: permissions attached to roles, people attached to roles.
VLAN / VPN Virtual LAN: logical segmentation of a switched network. Virtual private network: an encrypted tunnel across an untrusted network.

How to use these pages

Each technology child page follows the TR’s assessment skeleton. Category pages (Clauses 5–10) give the section introduction only. Cross-links point to the later normative parts that turn these technologies into requirements.