Insights

ISASecure and IEC 62443, explained with the numbers

What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.

Filteractive

8 articles match your filters

CSAIntermediate

Independent testing in ISASecure CSA: what the lab must test itself

ISASecure CSA flags 34 of its 166 functional requirements for testing by the lab itself. What the flag means, what happens to the rest, and what to prepare.

Sep 8, 20268 min readRead
CSAIntermediate

ISASecure vulnerability identification testing: how the pass threshold scales with security level

ISASecure VIT pass criteria: one severity band is added per security level, the scan is identical at every level, and a pass never requires zero findings.

Sep 8, 20268 min readRead
ICSAIntermediate

Cloud links, wireless radios and the per-interface rule in ISASecure ICSA

In ISASecure ICSA, cloud and wireless links are ordinary accessible interfaces. How the per-interface rule and the untrusted-network declaration set the effort.

Sep 8, 20268 min readRead
ICSAIntermediate

IIoT vulnerability testing: how ISASecure ICSA's two tiers set the pass threshold

ISASecure ICSA vulnerability testing: Core must address critical and high findings, Advanced adds medium. One scan, two filters; a pass is never zero findings.

Sep 8, 20268 min readRead
ICSAIntermediate

Independent testing in ISASecure ICSA: the 47 requirements the lab exercises

ISASecure ICSA flags 47 of its 182 functional requirements for testing by the lab itself, 40 of them at Core. What the flag means and what to prepare.

Sep 8, 20269 min readRead
SSAIntermediate

SSA SDA-S artifacts: the 74 lifecycle rows ISASecure checks for a system, and why fuzz and load results are among them

ISASecure SSA's SDA-S stream re-checks 74 assessable rows of the SDLA-312 lifecycle catalogue for the system as sold, fuzz and load coverage included.

Sep 8, 20268 min readRead
SSAIntermediate

ISASecure SSA vulnerability testing: the scan where each zone sets its own pass threshold

How VIT-S works in ISASecure SSA: one known-vulnerability scan of every IP-addressed component, with the pass threshold set per component by its zone's level.

Sep 8, 20268 min readRead
SSAIntermediate

Independent testing in ISASecure SSA: eleven flagged requirements, one scan, one reference system

ISASecure SSA flags 11 of its 116 assessable rows for lab testing, plus one vulnerability scan on one reference system. What the lab tests and reviews.

Sep 8, 20269 min readRead

Have a product or system to certify?

Talk to the assessors who wrote these articles about what applies to you.