What is SDLA?
Security Development Lifecycle Assurance (SDLA) is one of the ISASecure certification schemes. It verifies that a product supplier's development processes conform to the requirements of IEC 62443-4-1, which defines secure development lifecycle requirements for products used in industrial automation and control systems.
Scope
SDLA certification evaluates the organization's development processes, not individual products. It covers:
- Security management: Organization-level security governance
- Specification of security requirements: How security requirements are defined
- Secure by design: Architecture and design security practices
- Secure implementation: Coding standards and practices
- Security verification and validation testing: Testing methodologies
- Management of security-related issues: Vulnerability handling
- Security update management: Patch and update processes
- Security guidelines documentation: User documentation
Benefits
SDLA certification demonstrates to customers that an organization follows a mature, systematic approach to developing secure industrial products. It is often a prerequisite or differentiator in the OT product market.
Back to Glossary