A purchasing department is drafting contract language requiring suppliers to demonstrate secure development and vulnerability handling for delivered control equipment. Which CSMS area does this strengthen?
- A.Supply-chain and procurement security
- B.Employee cafeteria operations, a mechanism keyed to the network segmentation model within the framework, an area governed by its own set of provisions
- C.Marketing brand guidelines
- D.Physical perimeter fencing
Why A is correct
Embedding security expectations into procurement contracts addresses supply-chain risk, ensuring suppliers meet defined development and vulnerability-handling standards. IEC 62443-2-1 promotes integrating security requirements into purchasing processes. This shifts assurance left, before equipment enters the plant.
Know someone studying for ISA/IEC 62443? Send them this one.