ISASecure and IEC 62443, explained with the numbers
What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.
Filteractive
12 articles match your filters
The ACSSA assessment process: four phases and the report you receive
How an ISASecure ACSSA evaluation runs: the plan you approve, the four ACSSA-304 phases from risk assessment to report, and how to read the ACSSA-303 report.
An asset owner's installed IACS: IEC 62443 asset owner certification scope under ISASecure ACSSA, and the six documents that define it
ISASecure ACSSA certifies an asset owner's installed IACS, bounded by six change-controlled documents: who may apply, what is in scope and what is carved out.
IEC 62443 target security levels in ACSSA: the asset owner's level decides what is checked, and nothing is awarded
How ACSSA uses each zone's target security level from the asset owner's IEC 62443-3-2 risk assessment to decide what is checked, and why no level is awarded.
Service providers in ACSSA: IEC 62443-2-4, delegated tasks and the VIC shortcut
How ISASecure ACSSA evaluates an asset owner's service providers against IEC 62443-2-4: who counts, delegated tasks, the agreed list, NR-A and the VIC result.
CCSC explained: the four IEC 62443-4-2 constraints that apply to every component
IEC 62443-4-2 has a second axis beyond the seven foundational requirements: four common component security constraints. What each means for a CSA certificate.
SDA-C, FSA-C and VIT-C: what each ISASecure CSA assessment stream proves
The ISASecure CSA assessment process, stream by stream: what SDA-C, FSA-C and VIT-C each prove, the five result outcomes, the pass rule and the certificate.
CSA security levels 1 to 4: what each level actually adds
IEC 62443 security levels explained through ISASecure CSA: what SL 1 to SL 4 are built to resist, how many requirements each adds, and how to pick a target.
Cloud links, wireless radios and the per-interface rule in ISASecure ICSA
In ISASecure ICSA, cloud and wireless links are ordinary accessible interfaces. How the per-interface rule and the untrusted-network declaration set the effort.
The SDLA prerequisite for CSA, ICSA and SSA: one process audit, three product schemes
ISASecure CSA, ICSA and SSA each require a valid SDLA certificate. What the process audit settles once, what every product scheme re-checks, and how to plan.
One certificate, several levels: how ISASecure SSA assigns a capability security level per zone
How ISASecure SSA assigns an IEC 62443 capability security level to each zone of a system, why one certificate can carry several levels, and how to specify it.
How to read an ISASecure SSA certificate and report: zones, levels and user-enforced mitigations
How to read an ISASecure SSA certificate and its SSA-303 report: capability levels per zone, the ten report sections, and the mitigations the user must apply.
A system as sold: IEC 62443-3-3 system certification scope under ISASecure SSA, and what falls outside it
ISASecure SSA certifies a control-system product as sold, at a version, in a fixed or scalable layout: the four eligibility criteria and what falls outside.
Have a product or system to certify?
Talk to the assessors who wrote these articles about what applies to you.