ISASecure and IEC 62443, explained with the numbers
What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.
Filteractive
10 articles match your filters
Cloud links, wireless radios and the per-interface rule in ISASecure ICSA
In ISASecure ICSA, cloud and wireless links are ordinary accessible interfaces. How the per-interface rule and the untrusted-network declaration set the effort.
ISASecure ICSA Core vs Advanced: what the higher tier actually adds
ICSA Core vs Advanced explained: what each tier is for, how 158 requirements become 182, which 24 are added and which the lab tests, and how to choose.
IIoT device or IIoT gateway: how the two ISASecure ICSA types decide your scope
Which of ISASecure ICSA's two IIoT types your product is, how the IEC 62443-4-2 families split between device and gateway, and why one product can carry both.
SDA-IC: the 93 lifecycle requirements checked per IIoT component, and the five ICSA-only practices
What ICSA's SDA-IC review checks per IIoT component: 93 of the 118 IEC 62443-4-1 lifecycle requirements, 16 IIoT-specific rows and five ICSA-only practices.
The Security Maintenance Audit: how an ISASecure ICSA certificate stays valid
How the ISASecure ICSA Security Maintenance Audit works: four IEC 62443-4-1 requirements, four topics, when audits fall, findings, suspension, withdrawal.
The 24 IIoT-specific requirements ISASecure ICSA adds to IEC 62443-4-2
ISASecure ICSA adds 24 IIoT-specific requirements to the IEC 62443-4-2 base: 18 at both tiers, 6 at Advanced only. What they cover and how to prepare.
Advanced is SL 4, except when it is SL 3: the ISASecure ICSA tier-to-level trap
ICSA Advanced maps to SL 4 in the functional assessment but to SL 3 in vulnerability testing. Why the mappings diverge and how to read the certificate.
IIoT vulnerability testing: how ISASecure ICSA's two tiers set the pass threshold
ISASecure ICSA vulnerability testing: Core must address critical and high findings, Advanced adds medium. One scan, two filters; a pass is never zero findings.
What ISASecure ICSA certification actually evaluates
ISASecure ICSA certifies IIoT devices and gateways against IEC 62443-4-2: 182 requirements, two device types, a Core or Advanced tier and a maintenance audit.
Independent testing in ISASecure ICSA: the 47 requirements the lab exercises
ISASecure ICSA flags 47 of its 182 functional requirements for testing by the lab itself, 40 of them at Core. What the flag means and what to prepare.
Have a product or system to certify?
Talk to the assessors who wrote these articles about what applies to you.