Learn to Design and Assess Secure IACS Products Using ISA/IEC 62443 Standards
ISASecure ISA/IEC 62443 for Product Suppliers and Assessors (IC47) trains product suppliers to design, develop and support industrial automation and control system (IACS) products that conform to the ISA/IEC 62443 series and meet ISASecure certification expectations. This course emphasizes the standards and technical requirements that guide secure product development, including patch management, risk assessment, product security development lifecycle (SDLC) requirements and component technical security controls.IC47 also prepares assessors to certify and evaluate both products and security development lifecycles against the ISASecure programs, Security Development Lifecycle Assurance (SDLA), System Security Assurance (SSA) and Component Security Assurance (CSA). Participants learn threat modeling, assessment artifacts, requirements mapping to security levels and the reporting elements used in ISASecure assessments, enabling them to perform rigorous, consistent evaluations.
This course is intended for IACS product suppliers, system and component product architects, development engineers (hardware and software), internal auditors and IACS conformance/certification assessors (independent or employed by a certification and assessment body). It is also well suited for IT cybersecurity auditors and IACS engineers transitioning to IACS cybersecurity certifications and assessments.
NOTE: IC47 will fulfill some of the accreditation requirements for certification bodies related to personnel qualifications.
View Offerings by Format
Classroom (IC47)Length: 3 days |
Virtual Classroom (IC47V)Length: 3 days |
Visit our course formats page for a detailed description of each format.
Learning Objectives
- Recognize the basic principles of control systems.
- Identify different types of control systems.
- Identify the architectural requirements of control systems.
- Recognize why ISA/IEC 62443 standards are important.
- Determine which ISA/IEC 62443 standards are relevant to product development.
- Identify the principal roles and audience for the ISA/IEC 62443 standards.
- Identify the key ideas in the ISA/IEC 62443 series of standards.
- Define the basics of risk assessment, security zone partitioning and security level selection.
- Apply the basics of risk assessment, security zone partitioning and security level selection.
- Define the requirements for an ISASecure CSA, SSA or SDLA certification.
- Identify the requirements for a product security development lifecycle and the patch management process.
- Define the threat modeling process that product suppliers use for product risk assessment.
- Apply the requirements for the threat modeling process.
- Identify the criteria for being an ISASecure assessor.
- Define the criteria for SDLA certification Identify the assessment details for an SDLA assessment.
- Identify the artifacts generated by following the 62443-4-1 development processes.
- Describe the contents of an SDLA assessment report and certificate Identify the steps to assessing a product security development lifecycle.
- Identify requirement constraints that are common across all IACS systems and components.
- Identify the identification and authentication control (IAC) and use control (UC) security requirements for IACS systems and components.
- Identify the system integrity (SI) and resource availability (RA) security requirements for IACS systems and components.
- Identify the data confidentiality (DC), restricted data flow (RDF) and timely response to events (TRE) security requirements for IACS systems and components.
- Identify the association between security requirements and security levels.
- Identify the ISASecure SSA and CSA certification requirements.
- Identify the detailed assessment activities for an ISASecure SSA or CSA assessments.
- Describe the contents of an ISASecure SSA and CSA assessment reports.
- Apply the steps to assessing a product.
Topics Covered
- IACS Fundamentals
- Overview of ISA/IEC 62443 Series
- ISA/IEC 62443 Series Key Concepts
- Relevant ISA/IEC 62443 Standards and Technical Reports
- Part 2-3 Patch management in the IACS environment
- Part 3-2 Security risk assessment for system design
- Part 3-3 IACS system security requirements and security levels
- Part 4-1 IACS product security development lifecycle requirements
- Part 4-2 Technical security requirements for IACS components
- ISASecure Certification Programs
- SDLA
- SSA
- CSA
Recommended Prerequisites
Before taking this course, students should have a fundamental understanding of computers, networking and basic software development and deployment processes. Additionally, they should be familiar with cybersecurity as it relates to organizational or technical product areas. While not mandatory, it is advisable that students have relevant professional experience, such as working as an IT auditor, holding related certifications (e.g., CISA), having hands-on experience designing or implementing industrial automation and control systems (IACS) or experience as an IACS product provider.