The base SRs state the required system capability. Nested REs add capability for higher security levels; the From SL label identifies the first SL column in Annex B where each enhancement applies.
Teaching note: These summaries paraphrase the standard for learning and are not normative text. Confirm each SR, RE and security-level mapping in
Annex B. Apply the common constraints in
Clause 4, including preservation of essential functions.
SR and RE summaries
SR 2.1 – Authorization enforcement
Summary: Enforce assigned permissions whenever users, processes or devices request an operation.
RE(1) – Authorization enforcement for all users
From SL: 2+ · Annex B mapping
Summary: Apply authorisation checks consistently to human, software-process and device users.
RE(2) – Permission mapping to roles
From SL: 2+ · Annex B mapping
Summary: Map permissions to defined roles so access follows job and operational responsibilities.
RE(3) – Supervisor override
From SL: 3+ · Annex B mapping
Summary: Provide a controlled, accountable supervisor override for authorised exceptional operations.
RE(4) – Dual approval
From SL: 4+ · Annex B mapping
Summary: Require two authorised parties to approve designated high-consequence actions.
SR 2.2 – Wireless use control
Summary: Authorise, monitor and restrict the use of wireless capabilities.
RE(1) – Identify and report unauthorized wireless devices
From SL: 3+ · Annex B mapping
Summary: Detect and report wireless devices that have not been authorised.
SR 2.3 – Use control for portable and mobile devices
Summary: Control portable and mobile devices before and during connection to the control system.
RE(1) – Enforcement of security status of portable and mobile devices
From SL: 3+ · Annex B mapping
Summary: Check and enforce an acceptable device security state before permitting use.
SR 2.4 – Mobile code
Summary: Control scripts, applets and other mobile code before execution.
RE(1) – Mobile code integrity check
From SL: 3+ · Annex B mapping
Summary: Verify mobile-code integrity before the code is allowed to execute.
SR 2.5 – Session lock
Summary: Lock inactive sessions to prevent use by an unattended or unauthorised person.
SR 2.6 – Remote session termination
Summary: Provide controlled termination of remote sessions; Annex B introduces this base SR beginning at SL 2.
SR 2.7 – Concurrent session control
Summary: Limit simultaneous sessions where concurrency would increase risk.
SR 2.8 – Auditable events
Summary: Generate audit records for security-relevant and operationally important events.
RE(1) – Centrally managed, system-wide audit trail
From SL: 3+ · Annex B mapping
Summary: Consolidate and centrally manage audit information across the system.
SR 2.9 – Audit storage capacity
Summary: Provide enough audit storage and manage capacity to avoid silent loss of records.
RE(1) – Warn when audit record storage capacity threshold reached
From SL: 3+ · Annex B mapping
Summary: Alert responsible personnel before audit storage is exhausted.
SR 2.10 – Response to audit processing failures
Summary: Respond safely and visibly when audit collection, processing or storage fails.
SR 2.11 – Timestamps
Summary: Attach sufficiently accurate and consistent timestamps to audit records.
RE(1) – Internal time synchronization
From SL: 3+ · Annex B mapping
Summary: Synchronise component clocks to an internal authoritative time source.
RE(2) – Protection of time source integrity
From SL: 4+ · Annex B mapping
Summary: Protect time sources and synchronisation paths against manipulation.
SR 2.12 – Non-repudiation
Summary: Retain evidence that supports attribution of actions and prevents credible denial.
RE(1) – Non-repudiation for all users
From SL: 4+ · Annex B mapping
Summary: Provide non-repudiation evidence for human, software-process and device users.