← Home

IEC 62443-3-3 Clause 7 – System Integrity

ISA/IEC 62443-3-3, Clause 7 defines Foundational Requirement FR 3 (SI) and its associated system requirements (SRs) and requirement enhancements (REs).

The base SRs state the required system capability. Nested REs add capability for higher security levels; the From SL label identifies the first SL column in Annex B where each enhancement applies.

Teaching note: These summaries paraphrase the standard for learning and are not normative text. Confirm each SR, RE and security-level mapping in Annex B. Apply the common constraints in Clause 4, including preservation of essential functions.

Reference: ISA/IEC 62443-3-3, Clause 7
Related: Foundational Requirements | Clause 4 common constraints | Using SL-T to select SRs | FR / SL vector | Annex B SR / RE mapping | Security Levels

FR pages: FR 1 | FR 2 | FR 3 | FR 4 | FR 5 | FR 6 | FR 7


Purpose

Maintain the integrity of communications, software, information, sessions and security functions throughout control-system operation.

For an SL-C(SI) claim, implement the applicable base SRs and every enhancement selected by the target security level and risk assessment.


Associated technologies (teaching)

Protect physical cables and communications paths as well as logical protocols. Use malware protection, validate it safely with tools such as the EICAR test file, and govern software through software configuration management (SCM). Secure PLC programming practices are especially relevant to SR 3.5 through SR 3.7.


System requirements and requirement enhancements


SR and RE summaries

SR 3.1 – Communication integrity

Summary: Protect communicated information from unauthorised modification.

RE(1) – Cryptographic integrity protection

From SL: 3+ · Annex B mapping

Summary: Use cryptographic mechanisms to detect changes to communications.

SR 3.2 – Malicious code protection

Summary: Detect, prevent and respond to malicious code using controls suitable for industrial systems.

RE(1) – Malicious code protection at entry and exit points

From SL: 2+ · Annex B mapping

Summary: Apply malicious-code controls where information enters or leaves the system.

RE(2) – Central management and reporting for malicious code protection

From SL: 3+ · Annex B mapping

Summary: Centrally manage protection and collect system-wide status and alerts.

SR 3.3 – Security functionality verification

Summary: Verify that security functions operate correctly and report failures.

RE(1) – Automated security functionality verification

From SL: 3+ · Annex B mapping

Summary: Automate verification of security functions and reporting of the results.

RE(2) – Security functionality verification during normal operation

From SL: 4+ · Annex B mapping

Summary: Perform verification without taking the control system out of normal operation.

SR 3.4 – Software and information integrity

Summary: Detect unauthorised changes to software and information.

RE(1) – Automated notification of integrity violations

From SL: 3+ · Annex B mapping

Summary: Automatically notify responsible personnel when an integrity violation is detected.

SR 3.5 – Input validation

Summary: Validate input syntax, length and range before data affects control logic or security decisions.

SR 3.6 – Deterministic output

Summary: Place outputs in a known safe state when normal processing cannot be completed.

SR 3.7 – Error handling

Summary: Handle errors without exposing sensitive details or undermining essential functions.

SR 3.8 – Session integrity

Summary: Protect sessions against hijacking, replay and identifier misuse.

RE(1) – Invalidation of session IDs after session termination

From SL: 3+ · Annex B mapping

Summary: Invalidate identifiers promptly when their sessions terminate.

RE(2) – Unique session ID generation

From SL: 3+ · Annex B mapping

Summary: Generate a unique identifier for each session.

RE(3) – Randomness of session IDs

From SL: 4+ · Annex B mapping

Summary: Use sufficient randomness to make session identifiers impractical to predict.

SR 3.9 – Protection of audit information

Summary: Protect audit records and audit tools against unauthorised access, modification and deletion.

RE(1) – Audit records on write-once media

From SL: 4+ · Annex B mapping

Summary: Store audit records on media that prevents later alteration.

Key takeaways