UR E27 specifies security capabilities required by equipment vendors / OEMs per system category. Capabilities organised by IEC 62443-4-2 Component Requirements (CR) covering 7 Foundational Requirements (FR): FR 1 Identification and Authentication Control (CR 1.1-1.13); FR 2 Use Control (CR 2.1-2.12); FR 3 System Integrity (CR 3.1-3.9); FR 4 Data Confidentiality (CR 4.1-4.3); FR 5 Restricted Data Flow (CR 5.1-5.4); FR 6 Timely Response to Events (CR 6.1-6.2); FR 7 Resource Availability (CR 7.1-7.8). UR E27 specifies which CRs apply per Category I/II/III at which Security Level (SL): Category III SL 1 basic; Category II SL 1-2; Category I SL 2-3 (high resilience to advanced threats). Each capability has detailed requirements: e.g. CR 1.1 Human user identification + authentication; CR 1.2 Software process + device identification; CR 1.5 Authenticator management (password + key + token lifecycle); CR 2.1 Authorization enforcement; CR 3.1 Communication integrity (cryptographic protection of communications); CR 5.2 Zone boundary protection; CR 7.3 Control system backup. Equipment manufacturers must implement + test + document these capabilities per category and provide evidence to class society at type approval. IACS UR E27 + IEC 62443-4-2 + FR + CR + SL profile applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.