FR 5 — Restricted Data Flow (RDF)

    IEC 62443 FR 5 — Restricted Data Flow (RDF): how QuantLayer enforces approved paths with OT-safe enforcement and audit-ready evidence.

    IEC 62443
    FR 5
    OT/ICS
    6 min
    Last updated: 2026-01-22

    Overview

    Constrain communications to approved flows between zones and components; minimize paths and blast radius.

    QuantLayer control mapping

    • Zones & conduits modeled as segmentation policies
    • Allow-list flows by identity, protocol, and service
    • Observe-to-enforce rollout to avoid OT downtime
    • Automated containment by restricting egress/inbound on compromise

    Implementation steps

    • Scope by zone: identify where this FR is most critical (e.g., safety zone, engineering access, remote vendor conduit).
    • Start in observe mode: baseline behavior and identify necessary exceptions.
    • Enforce gradually: enable controls in phases aligned to maintenance windows; document exceptions.
    • Continuously verify: monitor drift and anomalies; automate response where safe.

    Evidence checklist

    • Conduit policy definitions and change approvals
    • Blocked/allowed flow telemetry and trends
    • Containment actions and outcomes
    Implementation note
    IEC 62443 compliance is achieved through a combination of people, process, and technology controls. QuantLayer helps you operationalize the technical controls (identity, segmentation, integrity, telemetry, response) while producing audit-ready evidence to support your CSMS and assurance activities.