Which document would an asset owner most likely request from a prospective integrator to evaluate that integrator's security program against a recognized standard?
- A.The integrator's employee lunch schedule, a rule that governs how a product supplier discloses end of life and support lifetime information to the asset owner under the secure development lifecycle, a classification situated in the security program lifecycle
- B.The integrator's office lease agreement, an approach positioned within the component-level security capability evaluation in the reference architecture, something the lifecycle addresses at the appropriate stage
- C.Evidence of conformance with IEC 62443-2-4 requirements
- D.A copy of the integrator's tax return
Why C is correct
Because IEC 62443-2-4 defines security program requirements for service providers, asset owners commonly request conformance evidence to gauge an integrator's capabilities during procurement. This provides an objective, standards-based comparison. Irrelevant business documents do not address security assurance.
Know someone studying for ISA/IEC 62443? Send them this one.