← Home

IEC 62443-3-3 Clause 9 – Restricted Data Flow

ISA/IEC 62443-3-3, Clause 9 defines Foundational Requirement FR 5 (RDF) and its associated system requirements (SRs) and requirement enhancements (REs).

The base SRs state the required system capability. Nested REs add capability for higher security levels; the From SL label identifies the first SL column in Annex B where each enhancement applies.

Teaching note: These summaries paraphrase the standard for learning and are not normative text. Confirm each SR, RE and security-level mapping in Annex B. Apply the common constraints in Clause 4, including preservation of essential functions.

Reference: ISA/IEC 62443-3-3, Clause 9
Related: Foundational Requirements | Clause 4 common constraints | Using SL-T to select SRs | FR / SL vector | Annex B SR / RE mapping | Security Levels | Switches and VLANs | Network Segmentation

FR pages: FR 1 | FR 2 | FR 3 | FR 4 | FR 5 | FR 6 | FR 7


Purpose

Restrict communications between zones and conduits so only explicitly authorised data flows can cross defined boundaries.

For an SL-C(RDF) claim, implement the applicable base SRs and every enhancement selected by the target security level and risk assessment.


Associated technologies (teaching)

Implement segmentation with VLANs, firewalls and data diodes, selecting controls for the required trust boundary and direction of flow. See switches and VLANs, network firewalls (3-1 Clause 6.1), network security devices and network segmentation. These measures support zone and conduit requirement ZCR 3.


System requirements and requirement enhancements


SR and RE summaries

SR 5.1 – Network segmentation

Summary: Partition networks into zones and conduits according to risk and security requirements.

RE(1) – Physical network segmentation

From SL: 2+ · Annex B mapping

Summary: Use physical segmentation where logical separation does not provide sufficient assurance.

RE(2) – Independence from non-control system networks

From SL: 3+ · Annex B mapping

Summary: Make control-system networks independent of non-control-system networks.

RE(3) – Isolation of critical networks

From SL: 4+ · Annex B mapping

Summary: Isolate networks supporting critical functions from other networks.

SR 5.2 – Zone boundary protection

Summary: Mediate and control communications crossing a zone boundary.

RE(1) – Deny by default, allow by exception

From SL: 2+ · Annex B mapping

Summary: Block boundary traffic unless a rule explicitly permits it.

RE(2) – Island mode

From SL: 3+ · Annex B mapping

Summary: Support continued operation when the zone is intentionally disconnected from external networks.

RE(3) – Fail close

From SL: 3+ · Annex B mapping

Summary: Move boundary protection to a closed state when the protection mechanism fails.

SR 5.3 – General purpose person-to-person communication restrictions

Summary: Restrict email, messaging and similar general-purpose communications that can introduce threats.

RE(1) – Prohibit all general purpose person-to-person communications

From SL: 3+ · Annex B mapping

Summary: Disallow these communication services entirely where the risk requires it.

SR 5.4 – Application partitioning

Summary: Separate applications and functions to limit unintended interaction and compromise propagation.

Key takeaways