What is 'secure by design' in the context of IEC 62443-4-1?
- A.Designing only the user interface to look secure, an obligation attached to the foundational requirement set, a point the framework develops in a dedicated part
- B.Relying on the deployment environment for all security, a criterion aligned with the conformance assessment scheme, an area governed by its own set of provisions
- C.Building security into the product from the beginning of the design phase rather than adding it later
- D.Adding security features after product release
Why C is correct
Secure by design means integrating security considerations into the product from the earliest design phase. IEC 62443-4-1 requires that security be a fundamental design consideration, not an afterthought added to a completed product.
Know someone studying for ISA/IEC 62443? Send them this one.