IEC 62443 Control Library
Full control catalogue mapped to IEC 62443-3-3 system requirements
Total Controls
34
Implemented
0
Partial
0
Not Implemented
34
Compensating
0
Select one Foundational Requirement to expand its System Requirements.
Requirements table — all FRs
| ID | Control | FR | SL | Type | Zones | Status | ISO 27001 | NIST CSF | Linked Policies |
|---|---|---|---|---|---|---|---|---|---|
| SR 7.8 | Control System Component Inventory The control system shall provide the capability to maintain an inventory of all control system components. | FR7 | SL 1SL 2SL 3SL 4 | Detective | — | Not Implemented | A.8.1.1 | Identify | No policy |
| SR 7.7 | Least Functionality The control system shall provide the capability to restrict control system capabilities to only those necessary for operational use. | FR7 | SL 1SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.12.6.2 | Protect | No policy |
| SR 7.6 | Network and Security Configuration Settings The control system shall provide the capability to notify designated personnel when configuration inconsistencies are detected. | FR7 | SL 1SL 2SL 3SL 4 | Detective | — | Not Implemented | A.12.1.2 | Detect | No policy |
| SR 7.5 | Emergency Power The control system shall provide the capability to switch to and from an emergency power supply. | FR7 | SL 1SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.11.2.2 | Protect | No policy |
| SR 7.4 | Control System Recovery and Reconstitution The control system shall provide the capability to recover and reconstitute after a failure or attack. | FR7 | SL 1SL 2SL 3SL 4 | Corrective | — | Not Implemented | A.17.1.2 | Recover | No policy |
| SR 7.3 | Control System Backup The control system shall provide the capability to back up and restore the control system configuration and state. | FR7 | SL 1SL 2SL 3SL 4 | Corrective | — | Not Implemented | A.12.3.1 | Recover | No policy |
| SR 7.1 | Denial of Service Protection The control system shall provide the capability to operate in a degraded mode during a DoS event. | FR7 | SL 1SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.17.1.1 | Protect | No policy |
| SR 6.2 | Continuous Monitoring The control system shall provide the capability to monitor security events continuously. | FR6 | SL 2SL 3SL 4 | Detective | — | Not Implemented | A.12.4.1 | Detect | No policy |
| SR 6.1 | Audit Log Accessibility The control system shall provide the capability to make audit logs available during investigation. | FR6 | SL 1SL 2SL 3SL 4 | Detective | — | Not Implemented | A.16.1.7 | Detect | No policy |
| SR 5.4 | Application Partitioning The control system shall provide the capability to support partitioning of control system components. | FR5 | SL 3SL 4 | Preventive | — | Not Implemented | A.13.1.3 | Protect | No policy |
| SR 5.3 | General Purpose Person-to-Person Communication Restrictions The control system shall provide the capability to prevent general-purpose person-to-person communications. | FR5 | SL 3SL 4 | Preventive | — | Not Implemented | A.13.1.1 | Protect | No policy |
| SR 5.2 | Zone Boundary Protection The control system shall provide the capability to monitor and control all communications at zone boundaries. | FR5 | SL 1SL 2SL 3SL 4 | Preventive | DMZEnterprise IT | Not Implemented | A.13.1.1 | Detect | POL-001 |
| SR 5.1 | Network Segmentation The control system shall provide the capability to segment control systems from other systems using a zone and conduit model. | FR5 | SL 1SL 2SL 3SL 4 | Preventive | DMZEnterprise IT | Not Implemented | A.13.1.3 | Protect | No policy |
| SR 4.2 | Information Persistence The control system shall provide the capability to purge or delete information to prevent unauthorized disclosure. | FR4 | SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.8.3.2 | Protect | No policy |
| SR 4.1 | Information Confidentiality The control system shall provide the capability to protect the confidentiality of information at rest and in transit. | FR4 | SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.10.1.1 | Protect | No policy |
| SR 3.6 | Deterministic Output The control system shall provide the capability to set outputs to a predetermined state if the control system fails. | FR3 | SL 2SL 3SL 4 | Corrective | — | Not Implemented | A.17.1.1 | Respond | No policy |
| SR 3.4 | Software and Information Integrity The control system shall provide the capability to detect, record, report, and protect against unauthorized changes to software and information. | FR3 | SL 1SL 2SL 3SL 4 | Detective | — | Not Implemented | A.12.5.1 | Detect | No policy |
| SR 3.3 | Security Functionality Verification The control system shall provide the capability to verify the intended operation of security functions. | FR3 | SL 1SL 2SL 3SL 4 | Detective | — | Not Implemented | A.14.2.8 | Detect | No policy |
| SR 3.2 | Malicious Code Protection The control system shall provide the capability to protect against malicious code introduction. | FR3 | SL 1SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.12.2.1 | Protect | No policy |
| SR 3.1 | Communication Integrity The control system shall provide the capability to protect the integrity of transmitted information. | FR3 | SL 1SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.13.2.3 | Protect | No policy |
| SR 2.12 | Non-Repudiation The control system shall provide the capability to determine whether a given human user took a particular action. | FR2 | SL 3SL 4 | Detective | — | Not Implemented | A.12.4.1 | Detect | No policy |
| SR 2.9 | Audit Storage Capacity The control system shall provide the capability to protect audit records against their loss due to lack of storage capacity. | FR2 | SL 1SL 2SL 3SL 4 | Detective | — | Not Implemented | A.12.4.1 | Detect | No policy |
| SR 2.8 | Auditable Events The control system shall provide the capability to generate audit records for defined auditable events. | FR2 | SL 1SL 2SL 3SL 4 | Detective | — | Not Implemented | A.12.4.1 | Detect | No policy |
| SR 2.4 | Mobile Code The control system shall provide the capability to enforce mobile code policies. | FR2 | SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.12.5.1 | Protect | No policy |
| SR 2.3 | Use Control for Portable and Mobile Devices The control system shall provide the capability to authorize portable and mobile device connections. | FR2 | SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.8.3.1 | Protect | No policy |
| SR 2.2 | Wireless Use Control The control system shall provide the capability to authorize wireless connections to the control system. | FR2 | SL 1SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.13.1.1 | Protect | No policy |
| SR 2.1 | Authorization Enforcement The control system shall provide the capability to enforce authorizations assigned to all human users. | FR2 | SL 1SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.9.4.1 | Protect | No policy |
| SR 1.8 | Public Key Infrastructure (PKI) Certificates The control system shall provide the capability to operate with PKI certificates as part of an integrated PKI. | FR1 | SL 3SL 4 | Preventive | — | Not Implemented | A.10.1.1 | Protect | No policy |
| SR 1.7 | Strength of Password-Based Authentication The control system shall provide the capability to enforce configurable password strength. | FR1 | SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.9.4.3 | Protect | No policy |
| SR 1.5 | Authenticator Management The control system shall provide the capability to manage authenticators including setting minimum password complexity. | FR1 | SL 1SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.9.3.1 | Protect | No policy |
| SR 1.4 | Identifier Management The control system shall provide the capability to support the management of identifiers. | FR1 | SL 1SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.9.2.1 | Protect | No policy |
| SR 1.3 | Account Management The control system shall provide the capability to manage all accounts used to access the control system. | FR1 | SL 1SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.9.2.1 | Protect | No policy |
| SR 1.2 | Software Process and Device Identification and Authentication The control system shall provide the capability to identify and authenticate all software processes and devices. | FR1 | SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.9.4.2 | Protect | No policy |
| SR 1.1 | Human User Identification and Authentication The control system shall provide the capability to identify and authenticate all human users on all interfaces. | FR1 | SL 1SL 2SL 3SL 4 | Preventive | — | Not Implemented | A.9.2.1 | Protect | No policy |