Glossary · OT cybersecurity
Foundational requirement
Also known as: FR
German: Grundlegende Anforderung
In IEC 62443, a foundational requirement (FR) is one of seven top-level groups into which system and component security requirements are organized: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability.
- OT security
- Standards
In one sentence
IEC 62443 groups its security requirements into seven foundational requirements, from identification and authentication control to resource availability.
Example
The integrator's compliance matrix lists each system requirement of IEC 62443-3-3 under its foundational requirement, for example network segmentation under FR 5, restricted data flow.
How it applies
- Engineering: IEC 62443-3-3 (systems) and IEC 62443-4-2 (components) define system and component requirements under the seven FRs, with requirement enhancements for higher security levels. A security level can be expressed per FR, so a zone might need a high level for integrity but a lower one for confidentiality.
- Product development: Suppliers map product features to the requirements under each FR to show the security capability of a component.
- Operation: The FRs are a practical checklist: who can log on (FR 1), what they can do (FR 2), whether software and data stay unaltered (FR 3), which data is protected (FR 4), where data may flow (FR 5), how events are detected and handled (FR 6), and whether the system stays available (FR 7).
- Documentation: Security manuals can use the seven FRs as a structure, which helps integrators find the information they need to build their own compliance evidence.
Foundational requirement vs. system requirement
An FR is a category. The testable statements are the system requirements (SR) and component requirements (CR) listed under it.