RealVNC logomark

RealVNC Viewer

Productivity

icon close circle

IEC 62443 Remote Access Requirements: What Leaders Need

Contents

A supplier’s remote-support request arrives while a production line is under pressure. If the connection reaches an engineering workstation without a clear approval, defined route, or accountable owner, operations teams must explain the decision long after the maintenance work ends.

IEC 62443 remote access requirements define a risk-based approach to connecting people with industrial systems. Each session needs a verified identity, a valid maintenance purpose, permissions limited to the approved task, and a managed path into the target zone. The controls and evidence must match the Security Level Target set for the system’s assessed operational risk.

Different assets create different consequences when a session goes wrong. IEC 62443-3-2:2020 requires teams to define the System under Consideration, assess risk, establish Security Level Targets, and organize assets into security zones connected by controlled conduits. Think of those zones as restricted areas across a plant: every doorway needs a stated purpose, an approved visitor, and rules that match the equipment beyond it.

This guide explains how Security Levels, Foundational Requirements, zones, and conduits shape remote-session decisions. It sets out the five decisions leaders need to govern – purpose, identity, authorization, path, and evidence – then covers the controls, audit tests, and common gaps that determine whether a policy holds up in real maintenance sessions.

Why are IEC 62443 remote access requirements risk-based?

Remote connectivity becomes an IACS architecture decision when it crosses a defined boundary into an industrial system. iec 62443 remote access requirements call for each pathway to be assessed against the assets it reaches, the operational consequence of disruption, and the Security Level Target (SL-T) set through risk assessment. A remote-access policy is only one part of that decision.

The International Electrotechnical Commission’s IEC 62443-3-2:2020 directs organizations to define the System under Consideration (SuC), partition it into security zones and conduits, assess risk, establish an SL-T, and document security requirements. Think of the SuC as the marked boundary around the equipment and connections a team has agreed to assess; without that boundary, access controls lack a clear operational context.

Policy adoption does not prove that those controls work in practice. The SANS Institute’s 2024 State of ICS/OT Cybersecurity found that 84% of respondents had a formal or informal remote-access policy. Leaders still need to test whether the policy identifies the target zone, accountable owner, approved purpose, and permitted route for each session.

A remote engineer connecting through a managed entry point to a packaging-cell engineering workstation follows a controlled conduit. A broadly routable connection from an external network to that same workstation does not provide the same design assurance. The difference lies in the documented route and the decision behind it.

Which OT pressures make remote sessions consequential?

Remote sessions affect production because they join external users to systems that influence physical operations. Manufacturing accounted for 25.7% of incidents across IBM X-Force’s ten most targeted industries in its 2024 executive summary, which gives access design a direct operational relevance.

  • Production continuity: A session affecting an engineering workstation or controller must preserve the availability requirements of the process it supports.
  • Supplier dependency: Original equipment manufacturers and integrators need maintenance access, but asset owners retain responsibility for approving its purpose and scope.
  • Legacy asset constraints: Older industrial equipment may not support modern identity controls directly, requiring a managed access boundary around it.
  • Auditability: A review must connect each session to a person, task, target, and accountable approver.

CISA’s 2023 industrial-control guidance recommends: “Eliminate all direct connections to critical operational assets.” That is complementary guidance rather than IEC 62443 wording, yet it gives executives a useful design test: access routes need a deliberate control point before they reach a critical zone.

Remote-access assumption IEC 62443 risk-based interpretation Executive implication
A VPN creates acceptable access The route must be assessed within the SuC and its zone-conduit design Require a documented path and owner
A named account authorizes a session Identity does not establish task, target, or duration Separate authentication from approval
One control set suits every asset SL-T reflects the risk of each zone and conduit Match safeguards to consequence
A written policy proves control Evidence must show the policy operated during real sessions Test records through sampling

How should leaders map sessions to IEC 62443?

Leaders should approve remote sessions through five linked decisions: purpose, identity, authorization, path, and evidence. This framework translates industrial remote-maintenance security controls into reviewable questions for asset owners, central security teams, and service providers. It does not replace a formal IEC 62443 conformity assessment.

Identity needs more than a network location or a supplier name. IBM’s X-Force Threat Intelligence Index 2024 reported that misuse of valid credentials rose 71% year over year and accounted for 30% of incidents IBM X-Force responded to in 2023. A valid credential shows who authenticated; it does not prove that the session was appropriate for a specific maintenance task.

IEC 62443-2-4:2023 identifies remote maintenance by IACS service providers as a governed security capability and notes that remote-access applications and the automation solution generally sit in different security zones. That separation forces clear decision rights between the supplier requesting access and the asset owner authorizing work.

  • Purpose: Record the approved maintenance activity, work order, and business reason for the session.
  • Identity: Verify the individual employee or supplier technician rather than relying on a shared account.
  • Authorization: Limit entitlements to the approved role, target asset, time window, and allowed actions.
  • Path: Define the managed entry point, zones crossed, and permitted route to the target.
  • Evidence: Retain records that let a reviewer reconstruct the decision and session activity.
Framework dimension Question to resolve Required owner Evidence source Common misreading
Purpose What maintenance work requires access? OT asset owner Work order or approval Connectivity itself is a business reason
Identity Which individual will connect? Supplier manager and identity owner Identity record and authentication event A supplier account identifies a person
Authorization What may that person do? Asset owner Role definition and session approval Authentication grants broad privilege
Path Which conduit reaches the target? OT architecture owner Zone-conduit diagram and route rule Any encrypted route is acceptable
Evidence What proves the session followed policy? Control owner Session record and review record A connection log is sufficient

What must the session record prove?

Audit-ready evidence proves why a session occurred, who performed it, what it reached, and whether its boundaries matched the approval. NIST SP 800-171 Rev. 3 calls for defined usage restrictions, connection requirements, prior authorization, and routing through authorized, managed access-control points. It complements IEC 62443; it does not substitute for the IACS risk assessment.

The SANS Institute’s 2024 survey reported that one-third of respondents had a next-generation secure remote-access platform. Technology adoption alone does not establish mature governance when approval and review records remain incomplete.

  • Approved purpose: The work order or documented operational reason.
  • Named identity: The individual employee or supplier technician.
  • Target: The asset, system, or zone reached.
  • Time boundary: The approved start, end, and duration.
  • Action boundary: The functions permitted during the session.
  • Review record: Evidence that an accountable team reviewed relevant activity.

How do zones and security levels shape access?

The target zone sets the starting point for a remote-access decision. IEC 62443-3-2 uses SL-T to express the protection required from assessed risk, so a pathway into a production-critical zone needs a stronger rationale than a pathway to a lower-consequence support system. A network diagram alone does not demonstrate that the resulting controls meet the documented requirement.

  • Low-consequence support access: Define the asset, accountable owner, approved task, and route before a session begins.
  • High-consequence control-zone access: Apply the same discipline with controls and evidence proportionate to the zone’s operational consequence and SL-T.

CISA’s guidance on managed remote arrangements reinforces the boundary principle: direct connectivity to critical operational assets should be removed. The design decision must remain tied to the organization’s own risk assessment and documented system requirements.

Which controls satisfy remote-session objectives?

A defensible remote-session design joins identity assurance, authorization enforcement, controlled pathways, protected communications, and reviewable activity records. These controls reinforce each other because an authenticated user still needs task-scoped rights, an approved route, and evidence that the session remained within its authorization. The final control set must reflect SL-T and the assessed risk of the IACS.

The International Society of Automation’s ISA/IEC 62443 standards overview identifies seven Foundational Requirements: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability. The exact titles, applicability, and Requirement Enhancements for SR 1.1, SR 2.1, and SR 5.1 require verification against the licensed IEC 62443-3-3 text.

A 2024 joint CISA, FBI, NSA, and DOE advisory documented VNC connections to OT human-machine interfaces through port 5900. Its recommended actions included changing default OT passwords, limiting internet reachability, and implementing multi-factor authentication (MFA) for OT-network access. The example shows why policy wording must be tested against reachable systems and actual authentication practices.

  1. Identify every human user (SR 1.1 anchor) – distinguish named identities from shared supplier credentials. Review identity records and authentication events.
  2. Enforce role- and task-scoped authorization (SR 2.1 anchor) – define access by approved maintenance function, target assets, and allowable session actions. Retain role definitions and approval records.
  3. Protect session confidentiality and integrity – assess encryption, endpoint authentication, and secure configuration as protections for communications and command integrity.
  4. Constrain the pathway between zones (SR 5.1 anchor) – require an approved route through a managed access-control point or OT demilitarized zone (OT DMZ). Review zone-conduit diagrams and route rules.
  5. Monitor, retain, and review security-relevant activity – link session logging and recording to incident response, supplier assurance, and periodic control testing.
Remote-session objective Typical control evidence Leadership decision supported Common audit error
Named identity Identity directory and authentication event Who may request access Treating a shared account as attribution
Task-scoped rights Role definition and approved work order What the user may do Granting standing privilege for a short task
Managed path Zone-conduit diagram and route configuration Which systems the session may reach Documenting segmentation without testing routes
Protected communications Security configuration record How commands and data are protected Assuming encryption resolves authorization gaps
Reviewable activity Session record, review record, and retention rule Whether policy operated Retaining logs that cannot reconstruct a session

Isolated controls do not create an assured design. MFA without task approval, segmentation without route review, or records without accountable review leaves a gap between stated policy and operating practice.

How do you build audit-ready OT access?

Audit-ready OT access is a recurring governance practice, not a document prepared before an assessment. The work begins by assigning decision rights across operations, cybersecurity, and service providers, then testing whether actual sessions follow those decisions.

Lesley Carhart, ICS security practitioner and SANS Institute author, writes that remote-access misuse remains a common initial entry route and recommends brokered, approved, and recorded remote sessions, validation of segmentation and entry points, and a centralized inventory of ICS/OT remote-access endpoints. Her guidance is directional practice advice, rather than IEC 62443 language.

  1. Inventory each access path: Gather network diagrams, contracts, and support procedures. Retire, redesign, or formally govern each route. Success means every route has an owner and documented target zone.
  2. Assign decision rights: Use a responsibility matrix, maintenance agreements, and zone ownership records to determine who approves routine and emergency sessions. Suppliers must not approve their own access.
  3. Define least-privilege session profiles: Link role, asset, time window, and permitted action to maintenance tasks and SL-T. A named user alone does not establish authorization.
  4. Preserve reviewable evidence: Retain approvals, authentication events, route data, and relevant session activity under a defined review cadence. A sample session must be reconstructable.
  5. Test exceptions and recovery: Define emergency authority, post-event review, and expiry conditions. Tabletop exercises must show that urgent access does not become permanent privilege.
Governance practice Evidence retained Implication for audits and operations
Access-path inventory Route register and target-zone record Reveals undocumented supplier entry points
Approval ownership Responsibility matrix and approvals Establishes accountable decision rights
Session profiles Role, task, and time-bound rules Aligns privilege with maintenance work
Evidence review Session samples and review records Demonstrates operating control
Exception testing Exercise results and post-event review Prevents urgent work from normalizing access

A 2025 SCADA case-study review found recurring remediation themes: remove default credentials, use individual logins, and enable MFA on remote channels, including maintenance access. Repeating this review cycle gives the Cybersecurity Management System (CSMS) evidence that its access controls remain effective as suppliers, assets, and operating conditions change.

Which remote-access gaps survive audits?

The gaps most likely to survive an audit are rarely invisible; they sit in the distance between written rules and sampled session records. Executives should test a small set of real employee, supplier, and emergency sessions before an audit or renewal, then ask whether each record proves an approved and bounded activity.

  • Identity drift: Shared, generic, or default accounts prevent reliable attribution.
  • Path drift: Direct or undocumented routes bypass the zone-and-conduit design rationale.
  • Privilege drift: Supplier accounts retain wider access or longer duration than approved work requires.
  • Evidence drift: Records cannot connect approval, identity, target asset, action, and reviewer.

NIST SP 800-171 Rev. 3 requires prior authorization, defined connection requirements, and routing through authorized managed access-control points. The 2024 government advisory also recommended limiting internet reachability, changing default OT passwords, and implementing MFA after documenting VNC access to OT interfaces. Neither finding automatically proves IEC 62443 nonconformance; applicability depends on scope, risk assessment, SL-T, and documented system requirements.

The practical test is straightforward: choose a completed supplier session and reconstruct the approval, identity, route, target, permissions, activity record, and reviewer. If the organization cannot do that, the control needs attention before the next audit window.

RealVNC and the IEC 62443 Access Problem

An approved OT remote-access policy loses force when teams cannot apply it consistently to internal engineers, original equipment manufacturers, integrators, and incident-response personnel. The workflow needs named identity, task-level authorization, a controlled entry route, and retained evidence, while asset owners remain accountable for the systems they permit others to reach.

RealVNC’s Emerging Threats in Remote Access Security research found that organizations using four or more remote-access tools had more than double the incident rate of organizations using fewer tools; the survey included 190 IT professionals. Consolidation does not establish industrial conformance, but it gives leaders a reason to reduce fragmented access administration and make ownership clearer.

RealVNC Connect supports controlled workflows through capabilities that map to the identity, authorization, third-party entry, and evidence needs discussed above:

  • MFA and single sign-on (SSO): Microsoft Entra ID or Okta SSO supports consistent identity assurance for Enterprise plans.
  • Role-based access controls (RBAC): Granular action-based permissions limit keyboard, mouse, and file-transfer actions according to the approved role.
  • Code Connect: Single-use nine-digit session codes provide time-bound access for third parties without issuing standing credentials.
  • Session evidence: Session monitoring, session recording, and detailed audit logs give authorized administrators material for oversight and review.

These capabilities help operationalize portions of security-level-aligned session governance. They do not make an organization IEC 62443 conformant by themselves: the asset owner must still complete risk assessment, zone-and-conduit design, SL-T decisions, procedures, and validation for the full IACS scope.

Final Words

Every remote session into an industrial system needs a decision trail that stands up after the maintenance work ends. iec 62443 remote access requirements give leaders a risk-based way to create that trail: define the System under Consideration, assess the target zone and conduit, and set a Security Level Target (SL-T). Then connect each session to a valid purpose, named identity, limited authorization, managed route, and reviewable evidence. A policy alone is not enough. Your team needs to reconstruct a completed employee, supplier, or emergency session from approval through to recorded activity and accountable review.

That discipline protects production operations from the slow drift that follows shared accounts, undocumented supplier paths, standing privilege, and records that cannot explain what happened. RealVNC Connect supports the operating layer of this model with multi-factor authentication (MFA) and single sign-on (SSO), role-based access controls (RBAC) with granular action-based permissions, plus session recording and detailed audit logs. These controls give asset owners a clearer way to apply their access decisions, while risk assessment, zone-and-conduit design, procedures, and validation remain their responsibility. Start a free trial of RealVNC Connect to evaluate controlled, auditable remote-support workflows for your OT access program.

FAQs

What framework governs controlled OT remote sessions?

IEC 62443 remote access requirements place each session within a documented industrial automation and control system (IACS) risk assessment. IEC 62443-3-2:2020 uses the system under consideration, security zones, conduits, and Security Level Targets (SL-T) to establish system security requirements. Remote access therefore needs to be assessed against the assets reached and the operational consequences involved.

What is the difference between an OT zone and a conduit?

An OT zone groups assets with shared security requirements, while a conduit controls communication between zones. IEC 62443-3-2:2020 uses both concepts to structure risk assessment and system requirements. CISA guidance also recommends eliminating direct connections to critical operational assets, so remote pathways need a managed boundary and documented purpose.

What is the IEC 62443 standard about?

IEC 62443 is a standards family for securing industrial automation and control systems across OT and industrial control system (ICS) environments. The International Society of Automation’s ISA/IEC 62443 overview describes the family’s coverage across asset owners, service providers, system integrators, and product suppliers. Decision-makers should apply the relevant parts to their system scope rather than treat the family as one product checklist.

What is required for remote access to an industrial system?

Remote access requires a justified purpose, a verified individual identity, defined authorization, a managed route, and evidence that the session followed its approval. The access design must also reflect the target zone, documented SL-T, and the operational consequences of disruption. NIST SP 800-171 Rev. 3 calls for prior authorization, defined connection requirements, and routing through authorized managed access-control points; it complements IEC 62443 rather than replacing it.

Which IEC 62443 standards apply to supplier maintenance?

IEC 62443-2-4:2023 addresses security requirements for IACS service providers, including remote maintenance where the access application and automation solution generally sit in separate security zones. IEC 62443-2-4:2023 supports a clear division of responsibility between the supplier requesting access and the asset owner approving it. Supplier access still needs prior authorization, defined scope, and a reviewable session record.

How does RealVNC support controlled OT remote-support workflows?

RealVNC supports controlled OT remote-support workflows through multi-factor authentication (MFA), single sign-on (SSO), role-based access controls (RBAC), and granular action-based permissions. Code Connect provides single-use, time-bound nine-digit session codes for third-party access, while session monitoring, session recording, and detailed audit logs support oversight and review. These capabilities support parts of a governed workflow; they do not replace IEC 62443 risk assessment, zone-and-conduit design, SL-T decisions, or asset-owner validation.

Learn more on this topic

Need to reach a Raspberry Pi from a Linux computer? Here's how to set up remote access with RealVNC Connect....
Remote troubleshooting industrial equipment can shorten diagnosis, but one unsafe change can stop production. Learn the controls that separate useful...
See how industrial automation security protects connected plants, controls remote access, and prioritizes recovery - before a hidden dependency changes...

Try RealVNC® Connect today for free

No credit card required for 14 days of free, secure and fast access to your devices. Upgrade or cancel anytime