← Home
IEC 62443-3-3 Clause 10 – Timely Response to Events
ISA/IEC 62443-3-3, Clause 10 defines Foundational Requirement FR 6 (TRE) and its associated system requirements (SRs) and requirement enhancements (REs).
The base SRs state the required system capability. Nested REs add capability for higher security levels; the From SL label identifies the first SL column in Annex B where each enhancement applies.
Teaching note: These summaries paraphrase the standard for learning and are not normative text. Confirm each SR, RE and security-level mapping in
Annex B. Apply the common constraints in
Clause 4, including preservation of essential functions.
Reference: ISA/IEC 62443-3-3, Clause 10
Related: Foundational Requirements | Clause 4 common constraints | Using SL-T to select SRs | FR / SL vector | Annex B SR / RE mapping | Security Levels
FR pages: FR 1 | FR 2 | FR 3 | FR 4 | FR 5 | FR 6 | FR 7
Purpose
Make security events visible and support prompt analysis, reporting and response before consequences escalate.
For an SL-C(TRE) claim, implement the applicable base SRs and every enhancement selected by the target security level and risk assessment.
Associated technologies (teaching)
Combine IDS, IPS and SIEM capabilities as part of detection in depth. Transport useful events with syslog and SNMP, and integrate required reporting with a Network and Information Systems (NIS) incident-reporting process.
System requirements and requirement enhancements
SR and RE summaries
SR 6.1 – Audit log accessibility
Summary: Make audit records available to authorised analysis and response functions.
RE(1) – Programmatic access to audit logs
From SL: 3+ · Annex B mapping
Summary: Provide a documented programmatic means for authorised tools to retrieve audit records.
SR 6.2 – Continuous monitoring
Summary: Continuously monitor security mechanisms and relevant system activity to support timely detection.
Key takeaways
- FR 6 (TRE) is implemented through the base SRs in Clause 10.
- REs are nested under their parent SR and add capability as the target security level rises.
- Use Annex B for the authoritative SL mapping and Clause 4 for constraints that apply across all foundational requirements.
- Technology supports the requirement, but architecture, configuration, operation and evidence determine whether the requirement is satisfied.