IEC 62443-4-2 expresses how a baseline requirement can be strengthened to reach higher security levels. What mechanism does the standard use for this?
- A.Optional compensating controls chosen by the asset owner, a benchmark treated under the system requirement catalogue, something the lifecycle addresses at the appropriate stage
- B.Supplementary controls listed only in an annex
- C.Requirement enhancements labeled RE(1), RE(2), and so on
- D.A separate maturity-level matrix
Why C is correct
Requirement Enhancements, written as RE(1), RE(2), etc., add capability on top of a base requirement and are what typically push a component's SL-C from 1 up to 2, 3, or 4. The base requirement alone usually satisfies SL 1.
Know someone studying for ISA/IEC 62443? Send them this one.