IEC 62443-4-1:2018
Security for industrial automation and control systems - Part 4-1: Secure product development lifecycle requirements
Sécurité des automatismes industriels et des systèmes de commande - Partie 4-1: Exigences relatives au cycle de développement de produit sécurisé
Standard number: | IEC 62443-4-1:2018 |
Released: | 2018-01-15 |
Language: | English |
IEC 62443-4-1:2018
IEC 62443-4:2018 specifies the process requirements for the secure development of products used in industrial automation and control systems. This specification is part of a series of standards that addresses the issue of security for industrial automation and control systems (IACS). IEC 62443-4 defines secure development life-cycle (SDL) requirements related to cyber security for products intended for use in the industrial automation and control systems environment and provides guidance on how to meet the requirements described for each element. The life-cycle description includes security requirements definition, secure design, secure implementation (including coding guidelines), verification and validation, defect management, patch management and product end-of-life. These requirements can be applied to new or existing processes for developing, maintaining and retiring hardware, software or firmware. Note that these requirements only apply to the developer and maintainer of the product, and are not applicable to the integrator or the user of the product. A summary list of the requirements is provided in Annex B.
Security for industrial automation and control systems - Part 4-2: Technical security requirements for IACS components
Industrial communication networks - Network and system security - Part 3-1: Security technologies for industrial automation and control systems
Security for industrial automation and control systems - Part 2-3: Patch management in the IACS environment