← Home
IEC 62443-3-3 Clause 9 – Restricted Data Flow
ISA/IEC 62443-3-3, Clause 9 defines Foundational Requirement FR 5 (RDF) and its associated system requirements (SRs) and requirement enhancements (REs).
The base SRs state the required system capability. Nested REs add capability for higher security levels; the From SL label identifies the first SL column in Annex B where each enhancement applies.
Teaching note: These summaries paraphrase the standard for learning and are not normative text. Confirm each SR, RE and security-level mapping in
Annex B. Apply the common constraints in
Clause 4, including preservation of essential functions.
Reference: ISA/IEC 62443-3-3, Clause 9
Related: Foundational Requirements | Clause 4 common constraints | Using SL-T to select SRs | FR / SL vector | Annex B SR / RE mapping | Security Levels | Switches and VLANs | Network Segmentation
FR pages: FR 1 | FR 2 | FR 3 | FR 4 | FR 5 | FR 6 | FR 7
Purpose
Restrict communications between zones and conduits so only explicitly authorised data flows can cross defined boundaries.
For an SL-C(RDF) claim, implement the applicable base SRs and every enhancement selected by the target security level and risk assessment.
System requirements and requirement enhancements
SR and RE summaries
SR 5.1 – Network segmentation
Summary: Partition networks into zones and conduits according to risk and security requirements.
RE(1) – Physical network segmentation
From SL: 2+ · Annex B mapping
Summary: Use physical segmentation where logical separation does not provide sufficient assurance.
RE(2) – Independence from non-control system networks
From SL: 3+ · Annex B mapping
Summary: Make control-system networks independent of non-control-system networks.
RE(3) – Isolation of critical networks
From SL: 4+ · Annex B mapping
Summary: Isolate networks supporting critical functions from other networks.
SR 5.2 – Zone boundary protection
Summary: Mediate and control communications crossing a zone boundary.
RE(1) – Deny by default, allow by exception
From SL: 2+ · Annex B mapping
Summary: Block boundary traffic unless a rule explicitly permits it.
RE(2) – Island mode
From SL: 3+ · Annex B mapping
Summary: Support continued operation when the zone is intentionally disconnected from external networks.
RE(3) – Fail close
From SL: 3+ · Annex B mapping
Summary: Move boundary protection to a closed state when the protection mechanism fails.
SR 5.3 – General purpose person-to-person communication restrictions
Summary: Restrict email, messaging and similar general-purpose communications that can introduce threats.
RE(1) – Prohibit all general purpose person-to-person communications
From SL: 3+ · Annex B mapping
Summary: Disallow these communication services entirely where the risk requires it.
SR 5.4 – Application partitioning
Summary: Separate applications and functions to limit unintended interaction and compromise propagation.
Key takeaways
- FR 5 (RDF) is implemented through the base SRs in Clause 9.
- REs are nested under their parent SR and add capability as the target security level rises.
- Use Annex B for the authoritative SL mapping and Clause 4 for constraints that apply across all foundational requirements.
- Technology supports the requirement, but architecture, configuration, operation and evidence determine whether the requirement is satisfied.