The team agrees how to work
Define and review product security requirements
- Responsibility
- Who prepares, reviews and approves the work
- Method
- Inputs, activities and the required review
- Records
- Scope, required behaviour and acceptance criteria
IEC 62443 / Product security
Keep secure development connected to the product being built. Sytance brings the architecture, security requirements, design decisions and verification records into one workspace.
Development lifecycle · IEC 62443-4-1
The management API must check the user's permission before accepting a configuration change.
Select a record to follow the requirement through design and verification.
Responsibilities, methods and review arrangements
Architecture, threats and security decisions
Trace requirements through design and verification
Start with the assessment scope
The part number follows the work being assessed. Select a scope to see where it sits.
The assessment looks at the secure development process and how it is applied. Product records should show how the team followed its procedures and assigned responsibilities.
Sytance supports lifecycle procedures and the product records used to apply them.
IEC 62443-4-1 in practice
A procedure sets out how the team works. For each product, the records explain which requirements were chosen, what design decisions were made and what verification was planned or performed.
The team agrees how to work
The management API must check the user's permission before accepting a configuration change.
Interface changeAffected analysisReview and verification
After the first release
A new interface, software component or vulnerability can change an earlier decision. Review the affected records and retain the rationale for the version being maintained.
Read the requirements in context
Source: IEC 62443-4-1 · ISA / IEC 62443