← Home

IEC 62443-3-3 Clause 5 – Identification and Authentication Control

ISA/IEC 62443-3-3, Clause 5 defines Foundational Requirement FR 1 (IAC) and its associated system requirements (SRs) and requirement enhancements (REs).

The base SRs state the required system capability. Nested REs add capability for higher security levels; the From SL label identifies the first SL column in Annex B where each enhancement applies.

Teaching note: These summaries paraphrase the standard for learning and are not normative text. Confirm each SR, RE and security-level mapping in Annex B. Apply the common constraints in Clause 4, including preservation of essential functions.

Reference: ISA/IEC 62443-3-3, Clause 5
Related: Foundational Requirements | Clause 4 common constraints | Using SL-T to select SRs | FR / SL vector | Annex B SR / RE mapping | Security Levels | IEC 62443-3-1 Clause 5 Authentication | Access Control | Multi-Factor Authentication (MFA) | Public Key Infrastructure (PKI) | Digital Certificates

FR pages: FR 1 | FR 2 | FR 3 | FR 4 | FR 5 | FR 6 | FR 7


Purpose

Identify and authenticate humans, software processes and devices before they interact with the control system, preventing unauthorised access and interrogation.

For an SL-C(IAC) claim, implement the applicable base SRs and every enhancement selected by the target security level and risk assessment.


Associated technologies (teaching)

Identity services such as Active Directory, RADIUS, LDAP and TACACS+ centralise authentication and account policy. Active Directory is also a high-value target: protect domain controllers, administrative paths, backups and service credentials as critical security assets.


System requirements and requirement enhancements


SR and RE summaries

SR 1.1 – Human user identification and authentication

Summary: Require every human user to be individually identified and authenticated before gaining control-system access.

RE(1) – Unique identification and authentication

From SL: 2+ · Annex B mapping

Summary: Use identities that uniquely attribute activity to one human user.

RE(2) – Multifactor authentication for untrusted networks

From SL: 3+ · Annex B mapping

Summary: Require multiple authentication factors when a human connects through an untrusted network.

RE(3) – Multifactor authentication for all networks

From SL: 4+ · Annex B mapping

Summary: Extend multifactor authentication to human access from every network path.

SR 1.2 – Software process and device identification and authentication

Summary: Identify and authenticate software processes and devices before permitting interaction with the system.

RE(1) – Unique identification and authentication

From SL: 3+ · Annex B mapping

Summary: Assign software processes and devices unique identities that can be authenticated and audited.

SR 1.3 – Account management

Summary: Create, modify, disable and remove accounts through a controlled lifecycle.

RE(1) – Unified account management

From SL: 3+ · Annex B mapping

Summary: Manage accounts consistently from a unified account-management capability.

SR 1.4 – Identifier management

Summary: Issue, manage and retire identifiers so they remain attributable and controlled.

SR 1.5 – Authenticator management

Summary: Protect and manage passwords, keys, tokens and other authenticators throughout their lifecycle.

RE(1) – Hardware security for software process identity credentials

From SL: 3+ · Annex B mapping

Summary: Protect software-process identity credentials with hardware-backed security.

SR 1.6 – Wireless access management

Summary: Control wireless access through approved identities and authenticated connections.

RE(1) – Unique identification and authentication

From SL: 2+ · Annex B mapping

Summary: Uniquely identify and authenticate users, devices or processes using wireless access.

SR 1.7 – Strength of password-based authentication

Summary: Apply password strength controls appropriate to the security level and account type.

RE(1) – Password generation and lifetime restrictions for human users

From SL: 3+ · Annex B mapping

Summary: Enforce stronger password generation and lifetime controls for human users.

RE(2) – Password lifetime restrictions for all users

From SL: 4+ · Annex B mapping

Summary: Apply password lifetime restrictions to every user type, including processes and devices.

SR 1.8 – Public key infrastructure (PKI) certificates

Summary: Validate and manage PKI certificates used to establish trusted identities.

See Public Key Infrastructure (PKI) and Digital Certificates.

SR 1.9 – Strength of public key authentication

Summary: Use public-key mechanisms and key protection appropriate to the claimed security level.

RE(1) – Hardware security for public key authentication

From SL: 3+ · Annex B mapping

Summary: Protect private keys and public-key authentication operations with hardware security.

SR 1.10 – Authenticator feedback

Summary: Conceal authentication information during entry and processing so observers cannot recover it.

SR 1.11 – Unsuccessful login attempts

Summary: Limit repeated failed logins while preserving the essential functions identified by Clause 4.

SR 1.12 – System use notification

Summary: Present an approved system-use notice before access is granted.

SR 1.13 – Access via untrusted networks

Summary: Monitor and control access arriving through networks outside the trusted control-system boundary.

RE(1) – Explicit access request approval

From SL: 2+ · Annex B mapping

Summary: Require explicit approval before allowing an access request from an untrusted network.

Key takeaways