The ISASecure Integrated Threat Analysis (ITA) Program is a certification scheme that certifies off-the-shelf automation and control systems to the ISA/IEC 62443 series of standards1. The ITA Program consists of three main components2:
Software Development Security Assurance (SDSA): This component evaluates the security lifecycle and practices of the product supplier, such as security requirements, design, implementation, verification, and maintenance. The SDSA certification is based on the ISA/IEC 62443-4-1 standard.
Functional Security Assessment (FSA): This component verifies the security functions and features implemented in the product, such as identification and authentication, access control, encryption, audit logging, and security management. The FSA certification is based on the ISA/IEC 62443-4-2 standard.
Communications Robustness Testing (CRT): This component tests the resilience of the product against network attacks, such as denial-of-service, fuzzing, spoofing, and replay. The CRT certification is based on the ISA/IEC 62443-4-2 and ISA/IEC 62443-3-3 standards .
[References:, 1: ISASecure - IEC 62443 Conformance Certification - Official Site, 2: ISASecure - IEC 62443 Conformance Certification - Official Site, [3]: ISA/IEC 62443-4-1: Secure Product Development Lifecycle Requirements, ISA, 2018., [4]: ISA/IEC 62443-4-2: Technical Security Requirements for IACS Components, ISA, 2019., [5]: ISA/IEC 62443-4-2: Technical Security Requirements for IACS Components, ISA, 2019., [6]: ISA/IEC 62443-3-3: System Security Requirements and Security Levels, ISA, 2013., ]
Submit