The base SRs state the required system capability. Nested REs add capability for higher security levels; the From SL label identifies the first SL column in Annex B where each enhancement applies.
Teaching note: These summaries paraphrase the standard for learning and are not normative text. Confirm each SR, RE and security-level mapping in
Annex B. Apply the common constraints in
Clause 4, including preservation of essential functions.
SR and RE summaries
SR 1.1 – Human user identification and authentication
Summary: Require every human user to be individually identified and authenticated before gaining control-system access.
RE(1) – Unique identification and authentication
From SL: 2+ · Annex B mapping
Summary: Use identities that uniquely attribute activity to one human user.
RE(2) – Multifactor authentication for untrusted networks
From SL: 3+ · Annex B mapping
Summary: Require multiple authentication factors when a human connects through an untrusted network.
RE(3) – Multifactor authentication for all networks
From SL: 4+ · Annex B mapping
Summary: Extend multifactor authentication to human access from every network path.
SR 1.2 – Software process and device identification and authentication
Summary: Identify and authenticate software processes and devices before permitting interaction with the system.
RE(1) – Unique identification and authentication
From SL: 3+ · Annex B mapping
Summary: Assign software processes and devices unique identities that can be authenticated and audited.
SR 1.3 – Account management
Summary: Create, modify, disable and remove accounts through a controlled lifecycle.
RE(1) – Unified account management
From SL: 3+ · Annex B mapping
Summary: Manage accounts consistently from a unified account-management capability.
SR 1.4 – Identifier management
Summary: Issue, manage and retire identifiers so they remain attributable and controlled.
SR 1.5 – Authenticator management
Summary: Protect and manage passwords, keys, tokens and other authenticators throughout their lifecycle.
RE(1) – Hardware security for software process identity credentials
From SL: 3+ · Annex B mapping
Summary: Protect software-process identity credentials with hardware-backed security.
SR 1.6 – Wireless access management
Summary: Control wireless access through approved identities and authenticated connections.
RE(1) – Unique identification and authentication
From SL: 2+ · Annex B mapping
Summary: Uniquely identify and authenticate users, devices or processes using wireless access.
SR 1.7 – Strength of password-based authentication
Summary: Apply password strength controls appropriate to the security level and account type.
RE(1) – Password generation and lifetime restrictions for human users
From SL: 3+ · Annex B mapping
Summary: Enforce stronger password generation and lifetime controls for human users.
RE(2) – Password lifetime restrictions for all users
From SL: 4+ · Annex B mapping
Summary: Apply password lifetime restrictions to every user type, including processes and devices.
SR 1.9 – Strength of public key authentication
Summary: Use public-key mechanisms and key protection appropriate to the claimed security level.
RE(1) – Hardware security for public key authentication
From SL: 3+ · Annex B mapping
Summary: Protect private keys and public-key authentication operations with hardware security.
SR 1.10 – Authenticator feedback
Summary: Conceal authentication information during entry and processing so observers cannot recover it.
SR 1.11 – Unsuccessful login attempts
Summary: Limit repeated failed logins while preserving the essential functions identified by Clause 4.
SR 1.12 – System use notification
Summary: Present an approved system-use notice before access is granted.
SR 1.13 – Access via untrusted networks
Summary: Monitor and control access arriving through networks outside the trusted control-system boundary.
RE(1) – Explicit access request approval
From SL: 2+ · Annex B mapping
Summary: Require explicit approval before allowing an access request from an untrusted network.