FR 3 — System Integrity (SI)
IEC 62443 FR 3 — System Integrity (SI): how QuantLayer detects and prevents unauthorized modifications with OT-safe enforcement and audit-ready evidence.
IEC 62443
FR 3
OT/ICS
6 min
Last updated: 2026-01-22Overview
Protect systems from unauthorized modification and detect integrity compromise (tamper, drift, malicious changes).
QuantLayer control mapping
- Secure boot / measured boot evidence collection
- Configuration and policy drift detection with alerts
- Immutable logging of changes and remediation actions
- Quarantine workflows when integrity is violated
Implementation steps
- Scope by zone: identify where this FR is most critical (e.g., safety zone, engineering access, remote vendor conduit).
- Start in observe mode: baseline behavior and identify necessary exceptions.
- Enforce gradually: enable controls in phases aligned to maintenance windows; document exceptions.
- Continuously verify: monitor drift and anomalies; automate response where safe.
Evidence checklist
- Integrity check results and drift events
- Change history (who/what/when) with signed artifacts
- Containment and remediation records
Implementation note
IEC 62443 compliance is achieved through a combination of people, process, and technology controls. QuantLayer helps you operationalize the technical controls (identity, segmentation, integrity, telemetry, response) while producing audit-ready evidence to support your CSMS and assurance activities.