Language:
    • Available Formats
    •  
    • Availability
    • Priced From ( in USD )
    • Secure PDF 🔒
    • Immediate download
    • $320.00
    • Add to Cart
    • Printed Edition
    • Ships in 1-2 business days
    • $320.00
    • Add to Cart

Customers Who Bought This Also Bought

 

About This Item

 

Full Description

Preface:

This is the first edition of CSA IEC 62443-4-1, Security for industrial automation and control systems — Part 4-1: Secure product development lifecycle requirements, which is an adoption without modification of the identically titled IEC (International Organization for Standardization) Standard 62443-4-1 (first edition, 2018-01). At the time of publication, IEC 62443-4-1:2018 is available from IEC in English only. CSA Group will publish the French version when it becomes available from IEC.

This Standard is one in a series of Standards developed by IEC/TC 65 on industrial automation networking security that are being adopted by CSA Group. This Standard specifies process requirements for the secure development of products used in industrial automation and control systems. It defines a secure development life-cycle (SDL) for the purpose of developing and maintaining secure products.

It is intended to be used by the developer and maintainer of the product, but not by the integrator or user of the product.

This Standard uses terminology and concepts specified in CAN/CSA-IEC/TS 62443-1-1:17, Industrial communication networks — Network and system security — Part 1-1: Terminology, concepts and models.

This Standard has been developed in compliance with Standards Council of Canada requirements for National Standards of Canada. It has been published as a National Standard of Canada by CSA Group.

Scope:

This part of IEC 62443 specifies process requirements for the secure development of products used in industrial automation and control systems. It defines a secure development life-cycle (SDL) for the purpose of developing and maintaining secure products. This life-cycle includes security requirements definition, secure design, secure implementation (including coding guidelines), verification and validation, defect management, patch management and product end-of-life. These requirements can be applied to new or existing processes for developing, maintaining and retiring hardware, software or firmware for new or existing products. These requirements apply to the developer and maintainer of the product, but not to the integrator or user of the product. A summary list of the requirements in this document can be found in Annex B.