Skip to main content
Back

IEC 62443-4-1:2018

Security for industrial automation and control systems - Part 4-1: Secure product development lifecycle requirements

General information

Valid from 15.01.2018
Directives or regulations
None

Standard history

Status
Date
Type
Name
15.01.2018
Main
IEC 62443-4:2018(E) specifies the process requirements for the secure development of products used in industrial automation and control systems. This specification is part of a series of standards that addresses the issue of security for industrial automation and control systems (IACS). IEC 62443-4 defines secure development life-cycle (SDL) requirements related to cyber security for products intended for use in the industrial automation and control systems environment and provides guidance on how to meet the requirements described for each element. The life-cycle description includes security requirements definition, secure design, secure implementation (including coding guidelines), verification and validation, defect management, patch management and product end-of-life. These requirements can be applied to new or existing processes for developing, maintaining and retiring hardware, software or firmware.
Note that these requirements only apply to the developer and maintainer of the product, and are not applicable to the integrator or the user of the product. A summary list of the requirements is provided in Annex B.

Required fields are indicated with *

*
*
*
PDF
446.86 € incl tax
Paper
446.86 € incl tax
Standard monitoring

Customers who bought this item also bought

Main

IEC 62443-3-2:2020

Security for industrial automation and control systems - Part 3-2: Security risk assessment for system design
Newest version Valid from 24.06.2020
Main

IEC 80001-1:2021

Application of risk management for IT-networks incorporating medical devices - Part 1: Safety, effectiveness and security in the implementation and use of connected medical devices or connected health software
Newest version Valid from 21.09.2021
Main

IEC TS 62443-1-1:2009

Industrial communication networks - Network and system security - Part 1-1: Terminology, concepts and models
Newest version Valid from 30.07.2009
Main

IEC TR 62443-3-1:2009

Industrial communication networks - Network and system security - Part 3-1: Security technologies for industrial automation and control systems
Newest version Valid from 30.07.2009