ISASecure and IEC 62443, explained with the numbers
What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.
Filteractive
5 articles match your filters
IEC 62443 target security levels in ACSSA: the asset owner's level decides what is checked, and nothing is awarded
How ACSSA uses each zone's target security level from the asset owner's IEC 62443-3-2 risk assessment to decide what is checked, and why no level is awarded.
CSA security levels 1 to 4: what each level actually adds
IEC 62443 security levels explained through ISASecure CSA: what SL 1 to SL 4 are built to resist, how many requirements each adds, and how to pick a target.
ISASecure vulnerability identification testing: how the pass threshold scales with security level
ISASecure VIT pass criteria: one severity band is added per security level, the scan is identical at every level, and a pass never requires zero findings.
One certificate, several levels: how ISASecure SSA assigns a capability security level per zone
How ISASecure SSA assigns an IEC 62443 capability security level to each zone of a system, why one certificate can carry several levels, and how to specify it.
ISASecure SSA vulnerability testing: the scan where each zone sets its own pass threshold
How VIT-S works in ISASecure SSA: one known-vulnerability scan of every IP-addressed component, with the pass threshold set per component by its zone's level.
Have a product or system to certify?
Talk to the assessors who wrote these articles about what applies to you.