← Home

IEC 62443-3-3 Clause 11 – Resource Availability

ISA/IEC 62443-3-3, Clause 11 defines Foundational Requirement FR 7 (RA) and its associated system requirements (SRs) and requirement enhancements (REs).

The base SRs state the required system capability. Nested REs add capability for higher security levels; the From SL label identifies the first SL column in Annex B where each enhancement applies.

Teaching note: These summaries paraphrase the standard for learning and are not normative text. Confirm each SR, RE and security-level mapping in Annex B. Apply the common constraints in Clause 4, including preservation of essential functions.

Reference: ISA/IEC 62443-3-3, Clause 11
Related: Foundational Requirements | Clause 4 common constraints | Using SL-T to select SRs | FR / SL vector | Annex B SR / RE mapping | Security Levels

FR pages: FR 1 | FR 2 | FR 3 | FR 4 | FR 5 | FR 6 | FR 7


Purpose

Preserve essential control-system services and resources through disruption, attack, failure and recovery.

For an SL-C(RA) claim, implement the applicable base SRs and every enhancement selected by the target security level and risk assessment.


Associated technologies (teaching)

Use rate limiting on firewalls to constrain abusive loads, tested VM snapshots as part of a wider backup strategy, UPS capacity for emergency power, and maintained inventory tools to understand available components and dependencies.


System requirements and requirement enhancements


SR and RE summaries

SR 7.1 – Denial of service protection

Summary: Protect essential functions against exhaustion or disruption caused by denial-of-service conditions.

RE(1) – Manage communication loads

From SL: 2+ · Annex B mapping

Summary: Shape, prioritise or limit communication loads to preserve essential traffic.

RE(2) – Limit denial of service effects

From SL: 3+ · Annex B mapping

Summary: Apply additional mechanisms that contain the operational effects of denial-of-service attacks.

SR 7.2 – Resource management

Summary: Manage processing, memory, storage and communications resources so essential functions remain available.

SR 7.3 – Control system backup

Summary: Back up information, configuration and software needed to restore the control system.

RE(1) – Backup integrity verification

From SL: 2+ · Annex B mapping

Summary: Verify backup integrity so corrupted or incomplete backups are detected.

RE(2) – Backup automation

From SL: 3+ · Annex B mapping

Summary: Automate scheduled backups and record whether they complete successfully.

SR 7.4 – Control system recovery and reconstitution

Summary: Restore the control system to a known, secure and operational state after disruption.

SR 7.5 – Emergency power

Summary: Provide emergency power sufficient to preserve essential functions or support an orderly shutdown.

SR 7.6 – Network and security configuration settings

Summary: Maintain and protect approved network and security configurations.

RE(1) – Machine-readable reporting of current security settings

From SL: 3+ · Annex B mapping

Summary: Provide current security settings in a machine-readable form for comparison and review.

SR 7.7 – Least functionality

Summary: Disable or remove unnecessary functions, ports, protocols and services.

SR 7.8 – Control system component inventory

Summary: Maintain an accurate inventory of control-system components and relevant attributes.

Key takeaways