IEC 62443 Control Library

Full control catalogue mapped to IEC 62443-3-3 system requirements

Total Controls

34

Implemented

0

Partial

0

Not Implemented

34

Compensating

0

Select one Foundational Requirement to expand its System Requirements.

Requirements table — all FRs

IDControlFRSLTypeZonesStatusISO 27001NIST CSFLinked Policies
SR 7.8

Control System Component Inventory

The control system shall provide the capability to maintain an inventory of all control system components.

FR7
SL 1SL 2SL 3SL 4
DetectiveNot ImplementedA.8.1.1IdentifyNo policy
SR 7.7

Least Functionality

The control system shall provide the capability to restrict control system capabilities to only those necessary for operational use.

FR7
SL 1SL 2SL 3SL 4
PreventiveNot ImplementedA.12.6.2ProtectNo policy
SR 7.6

Network and Security Configuration Settings

The control system shall provide the capability to notify designated personnel when configuration inconsistencies are detected.

FR7
SL 1SL 2SL 3SL 4
DetectiveNot ImplementedA.12.1.2DetectNo policy
SR 7.5

Emergency Power

The control system shall provide the capability to switch to and from an emergency power supply.

FR7
SL 1SL 2SL 3SL 4
PreventiveNot ImplementedA.11.2.2ProtectNo policy
SR 7.4

Control System Recovery and Reconstitution

The control system shall provide the capability to recover and reconstitute after a failure or attack.

FR7
SL 1SL 2SL 3SL 4
CorrectiveNot ImplementedA.17.1.2RecoverNo policy
SR 7.3

Control System Backup

The control system shall provide the capability to back up and restore the control system configuration and state.

FR7
SL 1SL 2SL 3SL 4
CorrectiveNot ImplementedA.12.3.1RecoverNo policy
SR 7.1

Denial of Service Protection

The control system shall provide the capability to operate in a degraded mode during a DoS event.

FR7
SL 1SL 2SL 3SL 4
PreventiveNot ImplementedA.17.1.1ProtectNo policy
SR 6.2

Continuous Monitoring

The control system shall provide the capability to monitor security events continuously.

FR6
SL 2SL 3SL 4
DetectiveNot ImplementedA.12.4.1DetectNo policy
SR 6.1

Audit Log Accessibility

The control system shall provide the capability to make audit logs available during investigation.

FR6
SL 1SL 2SL 3SL 4
DetectiveNot ImplementedA.16.1.7DetectNo policy
SR 5.4

Application Partitioning

The control system shall provide the capability to support partitioning of control system components.

FR5
SL 3SL 4
PreventiveNot ImplementedA.13.1.3ProtectNo policy
SR 5.3

General Purpose Person-to-Person Communication Restrictions

The control system shall provide the capability to prevent general-purpose person-to-person communications.

FR5
SL 3SL 4
PreventiveNot ImplementedA.13.1.1ProtectNo policy
SR 5.2

Zone Boundary Protection

The control system shall provide the capability to monitor and control all communications at zone boundaries.

FR5
SL 1SL 2SL 3SL 4
Preventive
DMZEnterprise IT
Not ImplementedA.13.1.1Detect
POL-001
SR 5.1

Network Segmentation

The control system shall provide the capability to segment control systems from other systems using a zone and conduit model.

FR5
SL 1SL 2SL 3SL 4
Preventive
DMZEnterprise IT
Not ImplementedA.13.1.3ProtectNo policy
SR 4.2

Information Persistence

The control system shall provide the capability to purge or delete information to prevent unauthorized disclosure.

FR4
SL 2SL 3SL 4
PreventiveNot ImplementedA.8.3.2ProtectNo policy
SR 4.1

Information Confidentiality

The control system shall provide the capability to protect the confidentiality of information at rest and in transit.

FR4
SL 2SL 3SL 4
PreventiveNot ImplementedA.10.1.1ProtectNo policy
SR 3.6

Deterministic Output

The control system shall provide the capability to set outputs to a predetermined state if the control system fails.

FR3
SL 2SL 3SL 4
CorrectiveNot ImplementedA.17.1.1RespondNo policy
SR 3.4

Software and Information Integrity

The control system shall provide the capability to detect, record, report, and protect against unauthorized changes to software and information.

FR3
SL 1SL 2SL 3SL 4
DetectiveNot ImplementedA.12.5.1DetectNo policy
SR 3.3

Security Functionality Verification

The control system shall provide the capability to verify the intended operation of security functions.

FR3
SL 1SL 2SL 3SL 4
DetectiveNot ImplementedA.14.2.8DetectNo policy
SR 3.2

Malicious Code Protection

The control system shall provide the capability to protect against malicious code introduction.

FR3
SL 1SL 2SL 3SL 4
PreventiveNot ImplementedA.12.2.1ProtectNo policy
SR 3.1

Communication Integrity

The control system shall provide the capability to protect the integrity of transmitted information.

FR3
SL 1SL 2SL 3SL 4
PreventiveNot ImplementedA.13.2.3ProtectNo policy
SR 2.12

Non-Repudiation

The control system shall provide the capability to determine whether a given human user took a particular action.

FR2
SL 3SL 4
DetectiveNot ImplementedA.12.4.1DetectNo policy
SR 2.9

Audit Storage Capacity

The control system shall provide the capability to protect audit records against their loss due to lack of storage capacity.

FR2
SL 1SL 2SL 3SL 4
DetectiveNot ImplementedA.12.4.1DetectNo policy
SR 2.8

Auditable Events

The control system shall provide the capability to generate audit records for defined auditable events.

FR2
SL 1SL 2SL 3SL 4
DetectiveNot ImplementedA.12.4.1DetectNo policy
SR 2.4

Mobile Code

The control system shall provide the capability to enforce mobile code policies.

FR2
SL 2SL 3SL 4
PreventiveNot ImplementedA.12.5.1ProtectNo policy
SR 2.3

Use Control for Portable and Mobile Devices

The control system shall provide the capability to authorize portable and mobile device connections.

FR2
SL 2SL 3SL 4
PreventiveNot ImplementedA.8.3.1ProtectNo policy
SR 2.2

Wireless Use Control

The control system shall provide the capability to authorize wireless connections to the control system.

FR2
SL 1SL 2SL 3SL 4
PreventiveNot ImplementedA.13.1.1ProtectNo policy
SR 2.1

Authorization Enforcement

The control system shall provide the capability to enforce authorizations assigned to all human users.

FR2
SL 1SL 2SL 3SL 4
PreventiveNot ImplementedA.9.4.1ProtectNo policy
SR 1.8

Public Key Infrastructure (PKI) Certificates

The control system shall provide the capability to operate with PKI certificates as part of an integrated PKI.

FR1
SL 3SL 4
PreventiveNot ImplementedA.10.1.1ProtectNo policy
SR 1.7

Strength of Password-Based Authentication

The control system shall provide the capability to enforce configurable password strength.

FR1
SL 2SL 3SL 4
PreventiveNot ImplementedA.9.4.3ProtectNo policy
SR 1.5

Authenticator Management

The control system shall provide the capability to manage authenticators including setting minimum password complexity.

FR1
SL 1SL 2SL 3SL 4
PreventiveNot ImplementedA.9.3.1ProtectNo policy
SR 1.4

Identifier Management

The control system shall provide the capability to support the management of identifiers.

FR1
SL 1SL 2SL 3SL 4
PreventiveNot ImplementedA.9.2.1ProtectNo policy
SR 1.3

Account Management

The control system shall provide the capability to manage all accounts used to access the control system.

FR1
SL 1SL 2SL 3SL 4
PreventiveNot ImplementedA.9.2.1ProtectNo policy
SR 1.2

Software Process and Device Identification and Authentication

The control system shall provide the capability to identify and authenticate all software processes and devices.

FR1
SL 2SL 3SL 4
PreventiveNot ImplementedA.9.4.2ProtectNo policy
SR 1.1

Human User Identification and Authentication

The control system shall provide the capability to identify and authenticate all human users on all interfaces.

FR1
SL 1SL 2SL 3SL 4
PreventiveNot ImplementedA.9.2.1ProtectNo policy