ISASecure and IEC 62443, explained with the numbers
What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.
Filteractive
9 articles match your filters
How ACSSA assesses IEC 62443-2-1 requirements: 89 composite verdicts from four standards
How ISASecure ACSSA folds IEC 62443-2-4, 3-2 and 3-3 results into one composite verdict per IEC 62443-2-1 requirement, and what makes a verdict fail.
IEC 62443 zone sampling in an ACSSA assessment: how zones, conduits and systems are sampled at maturity level 3
Where ISASecure ACSSA samples zones, device-bearing conduits and systems at maturity level 3, how the evaluator chooses the sample, and what to have ready.
What it takes to reach SL 3 in ISASecure CSA, by component type
Moving from SL 2 to SL 3 in ISASecure CSA adds 23 IEC 62443-4-2 requirements, 22 of them enhancements. What the step costs by component type and by FR.
Where fuzzing, load testing and penetration testing actually live in ISASecure CSA
Suppliers often expect the certification lab to fuzz and pen-test their product. It does not. Who performs each kind of security test in a CSA evaluation, what the lab checks instead, and what to prepare.
Advanced is SL 4, except when it is SL 3: the ISASecure ICSA tier-to-level trap
ICSA Advanced maps to SL 4 in the functional assessment but to SL 3 in vulnerability testing. Why the mappings diverge and how to read the certificate.
Fuzz, load, penetration and abuse-case testing: what the IEC 62443-4-1 SVV practice asks of a supplier
The SVV practice is where ISASecure SDLA is strictest: five IEC 62443-4-1 requirements, 20 assessable rows and a named test type behind most of them.
IEC 62443-4-1 process audit: the 23 SDLA rows no product evaluation examines
23 ISASecure SDLA-312 rows are checked only in the SDLA process audit, on Perseus's reading of its activity columns: defect handling, coding rules, pen testing.
Reference layouts and scalable systems: how one ISASecure SSA certificate covers a family of configurations
How ISASecure SSA certifies a scalable IEC 62443-3-3 system: zone specifications, layouts in scope, the reference layout the lab tests, and nine submissions.
What it takes to move a zone from SL 2 to SL 3 in ISASecure SSA
Raising a zone from SL 2 to SL 3 in ISASecure SSA adds 30 IEC 62443-3-3 rows: two base requirements and 28 enhancements, two of them lab-tested. All 30, by FR.
Have a product or system to certify?
Talk to the assessors who wrote these articles about what applies to you.