← Home

IEC 62443-3-3 Clause 10 – Timely Response to Events

ISA/IEC 62443-3-3, Clause 10 defines Foundational Requirement FR 6 (TRE) and its associated system requirements (SRs) and requirement enhancements (REs).

The base SRs state the required system capability. Nested REs add capability for higher security levels; the From SL label identifies the first SL column in Annex B where each enhancement applies.

Teaching note: These summaries paraphrase the standard for learning and are not normative text. Confirm each SR, RE and security-level mapping in Annex B. Apply the common constraints in Clause 4, including preservation of essential functions.

Reference: ISA/IEC 62443-3-3, Clause 10
Related: Foundational Requirements | Clause 4 common constraints | Using SL-T to select SRs | FR / SL vector | Annex B SR / RE mapping | Security Levels

FR pages: FR 1 | FR 2 | FR 3 | FR 4 | FR 5 | FR 6 | FR 7


Purpose

Make security events visible and support prompt analysis, reporting and response before consequences escalate.

For an SL-C(TRE) claim, implement the applicable base SRs and every enhancement selected by the target security level and risk assessment.


Associated technologies (teaching)

Combine IDS, IPS and SIEM capabilities as part of detection in depth. Transport useful events with syslog and SNMP, and integrate required reporting with a Network and Information Systems (NIS) incident-reporting process.


System requirements and requirement enhancements


SR and RE summaries

SR 6.1 – Audit log accessibility

Summary: Make audit records available to authorised analysis and response functions.

RE(1) – Programmatic access to audit logs

From SL: 3+ · Annex B mapping

Summary: Provide a documented programmatic means for authorised tools to retrieve audit records.

SR 6.2 – Continuous monitoring

Summary: Continuously monitor security mechanisms and relevant system activity to support timely detection.

Key takeaways