Skip to main content

IEC 62443 / Product security

IEC 62443Secure product development

Keep secure development connected to the product being built. Sytance brings the architecture, security requirements, design decisions and verification records into one workspace.

Development lifecycle · IEC 62443-4-1

Industrial controller / Product recordsv1.0
Product recordsArchitectureDocumentationIEC 62443-4-1
REQ-014For review

Restrict changes to the controller configuration

The management API must check the user's permission before accepting a configuration change.

Linked analysis
Threat: a read-only user changes the operating configuration.
Record to retain
Scope, required behaviour and acceptance criteria

Select a record to follow the requirement through design and verification.

01

Define the process

Responsibilities, methods and review arrangements

02

Work on the product

Architecture, threats and security decisions

03

Review the records

Trace requirements through design and verification

Start with the assessment scope

One series. Different assessment scopes.

The part number follows the work being assessed. Select a scope to see where it sits.

Process scopeIEC 62443-4-1

How the supplier develops and maintains the product

The assessment looks at the secure development process and how it is applied. Product records should show how the team followed its procedures and assigned responsibilities.

Sytance supports lifecycle procedures and the product records used to apply them.

IEC 62443-4-1 in practice

Follow a security requirement through design and verification.

A procedure sets out how the team works. For each product, the records explain which requirements were chosen, what design decisions were made and what verification was planned or performed.

Organisation / Procedure

The team agrees how to work

Define and review product security requirements

Responsibility
Who prepares, reviews and approves the work
Method
Inputs, activities and the required review
Records
Scope, required behaviour and acceptance criteria
Industrial controller / Examplev1.0
REQ-014For review

Restrict changes to the controller configuration

The management API must check the user's permission before accepting a configuration change.

Source records feed the document preview
Product maintenance
v1.0v1.1

Interface changeAffected analysisReview and verification

  • Review changed permissions and data flows
  • Update the linked requirements and designs
  • Retain verification results for the release

After the first release

Keep the analysis current as the product changes.

A new interface, software component or vulnerability can change an earlier decision. Review the affected records and retain the rationale for the version being maintained.