← Home
IEC 62443-3-3 Clause 8 – Data Confidentiality
ISA/IEC 62443-3-3, Clause 8 defines Foundational Requirement FR 4 (DC) and its associated system requirements (SRs) and requirement enhancements (REs).
The base SRs state the required system capability. Nested REs add capability for higher security levels; the From SL label identifies the first SL column in Annex B where each enhancement applies.
Teaching note: These summaries paraphrase the standard for learning and are not normative text. Confirm each SR, RE and security-level mapping in
Annex B. Apply the common constraints in
Clause 4, including preservation of essential functions.
Reference: ISA/IEC 62443-3-3, Clause 8
Related: Foundational Requirements | Clause 4 common constraints | Using SL-T to select SRs | FR / SL vector | Annex B SR / RE mapping | Security Levels
FR pages: FR 1 | FR 2 | FR 3 | FR 4 | FR 5 | FR 6 | FR 7
Purpose
Protect sensitive information from unauthorised disclosure while stored, processed and communicated.
For an SL-C(DC) claim, implement the applicable base SRs and every enhancement selected by the target security level and risk assessment.
Associated technologies (teaching)
Use encryption where confidentiality risk warrants it, while also applying physical security to devices and removable media. Enable and correctly configure encryption in OPC UA; use a controlled VPN when traffic must cross an untrusted network.
System requirements and requirement enhancements
SR and RE summaries
SR 4.1 – Information confidentiality
Summary: Protect confidential information according to its sensitivity and exposure paths.
RE(1) – Confidentiality at rest and across untrusted networks
From SL: 2+ · Annex B mapping
Summary: Protect confidential information in storage and while traversing untrusted networks.
RE(2) – Confidentiality across zone boundaries
From SL: 4+ · Annex B mapping
Summary: Apply confidentiality protection whenever sensitive information crosses zone boundaries.
SR 4.2 – Information persistence
Summary: Prevent residual sensitive information from remaining available after resources are released.
RE(1) – Purging of shared memory resources
From SL: 3+ · Annex B mapping
Summary: Purge shared memory before it is reassigned to another process or user.
SR 4.3 – Use of cryptography
Summary: Use accepted cryptographic mechanisms with appropriate key management where cryptography is required.
Key takeaways
- FR 4 (DC) is implemented through the base SRs in Clause 8.
- REs are nested under their parent SR and add capability as the target security level rises.
- Use Annex B for the authoritative SL mapping and Clause 4 for constraints that apply across all foundational requirements.
- Technology supports the requirement, but architecture, configuration, operation and evidence determine whether the requirement is satisfied.