An asset owner is documenting the seven Foundational Requirements of IEC 62443-3-3. Which foundational requirement ensures that only authenticated users and devices can be granted access before any authorization is evaluated?
- A.FR 1 Identification and Authentication Control
- B.FR 3 System Integrity
- C.FR 5 Restricted Data Flow, an activity organized under the component-level security capability evaluation for greenfield projects
- D.FR 2 Use Control
Why A is correct
FR 1 (Identification and Authentication Control) establishes that users, devices, and software processes must be uniquely identified and authenticated before any access is granted. Authorization decisions, governed by FR 2 (Use Control), are only meaningful once identity has been reliably established.
Know someone studying for ISA/IEC 62443? Send them this one.