Insights

ISASecure and IEC 62443, explained with the numbers

What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.

Filteractive

10 articles match your filters

SDLAIntermediate

SDLA certificate validity and recertification: how an ISASecure SDLA certificate is kept

How long an ISASecure SDLA certificate lasts, 36 or 12 months, how a recertification audit renews it, and why the scheme has no surveillance or suspension.

Sep 8, 20268 min readRead
SDLAIntermediate

IEC 62443-4-1 defect and update management: the SDLA practices product certifications come back to

How ISASecure SDLA evaluates IEC 62443-4-1 defect and update management: 15 rows, most seen only in the process audit, and the four requirements ICSA revisits.

Sep 8, 20269 min readRead
SDLAIntermediate

Full or readiness evaluation: the SDLA choice that sets your certificate at 36 or 12 months

ISASecure SDLA has two evaluation methods. One requirement passed by readiness evaluation sets the certificate at 12 months, not 36. The 21 rows that decide it.

Sep 8, 20269 min readRead
SDLAIntermediate

What counts as a major nonconformity in an IEC 62443-4-1 audit: the 31 SDLA minimum requirements

In an ISASecure SDLA audit a finding is major when no evidence exists, or when one of 31 minimum requirements is applied inconsistently. The full list.

Sep 8, 202610 min readRead
SDLAIntermediate

IEC 62443-4-1 certification levels: why ISASecure SDLA has none and every requirement must pass

ISASecure SDLA carried certification levels until 2018. Today it has none, and no maturity level either: every applicable IEC 62443-4-1 requirement must pass.

Sep 8, 20268 min readRead
SDLAIntermediate

The SDLA prerequisite for CSA, ICSA and SSA: one process audit, three product schemes

ISASecure CSA, ICSA and SSA each require a valid SDLA certificate. What the process audit settles once, what every product scheme re-checks, and how to plan.

Sep 8, 20269 min readRead
SDLAIntermediate

IEC 62443-4-1 security guidelines and hardening: the SDLA practice with the most minimum requirements

ISASecure SDLA and the IEC 62443-4-1 security guidelines practice: 7 requirements, 17 rows, 10 minimum requirements, no mandatory artifacts, examined twice.

Sep 8, 20269 min readRead
SDLADeep dive

Fuzz, load, penetration and abuse-case testing: what the IEC 62443-4-1 SVV practice asks of a supplier

The SVV practice is where ISASecure SDLA is strictest: five IEC 62443-4-1 requirements, 20 assessable rows and a named test type behind most of them.

Sep 8, 20269 min readRead
SDLAIntroductory

What is ISASecure SDLA, and what does the certificate actually certify?

ISASecure SDLA certifies a development organisation and a versioned development process against IEC 62443-4-1: eight practices, 47 requirements, no levels.

Sep 8, 20268 min readRead
SDLADeep dive

IEC 62443-4-1 process audit: the 23 SDLA rows no product evaluation examines

23 ISASecure SDLA-312 rows are checked only in the SDLA process audit, on Perseus's reading of its activity columns: defect handling, coding rules, pen testing.

Sep 8, 20269 min readRead

Have a product or system to certify?

Talk to the assessors who wrote these articles about what applies to you.