KionelLAB WORKFLOWS

GUIDE · UPDATED 2026

IEC 62443 and the file that crosses the air gap

An air gap is a conduit with no cable. IEC 62443 still expects it to be controlled: who may move data across, how its integrity is checked, and what is recorded. The weakest point is usually the moment a file changes zones.

Written by Taha Bayar, who builds Kionel. Kionel is one of the options below; the comparison is meant to be usable even if you choose another.

This is not compliance advice. Map the requirements to your own security level targets with your integrator or assessor.

The requirements a transfer touches (IEC 62443-3-3)

RequirementWhat it asks, in plain termsWhat answers it for a file transfer
SR 2.3 Use control for portable and mobile devicesPortable devices and media are restricted and controlled.Removing USB media from the route; a controlled, named receiving device.
SR 3.4 Software and information integrityUnauthorised changes to software and information can be detected.A SHA-256 taken on the source and checked on arrival, bound to a signature.
SR 3.1 Communication integrityTransmitted information is protected against modification.Authenticated encryption end to end, so a modified transfer fails.
SR 4.1 Information confidentialityInformation in transit is protected where required.Encryption to the receiving device; an image of the screen is ciphertext.
SR 2.8 Auditable eventsSecurity-relevant events are recorded.A record per transfer: what, from which device, to which device, when, for which ticket.

Out of the zone is the easy half

Exporting logs, reports and recipes needs only a screen on the source. Bringing patches and firmware into a zone is harder for any optical method: the target must have a camera, and it must verify what it receives before use. For inbound patches, a validated media process or a one-way conduit with integrity checks is usually the right answer; an optical route can still carry the signed hash so the target can verify a package that arrived another way.

A checklist you can apply to any route

  1. Is the route named in your zone and conduit model, with an owner?
  2. Is every file's hash taken at the source and checked at the destination?
  3. Is each transfer tied to a ticket, work order or change request?
  4. Can an assessor verify the record later without calling the vendor?
  5. Does the route bring any removable media into the zone?

Where Kionel fits

Kionel answers points 2 to 5 for small outbound files and for sealed proofs, with records that verify offline under a free Apache-2.0 tool. It does not scan content and it is not certified; see the limits.

Kionel for OT Verify a record