A plant must define how operating system patches for control systems are evaluated and deployed. Which IEC 62443 part addresses patch management directly?
- A.Part 3-2 on risk assessment for system design
- B.Part 3-1 on security technologies for control systems
- C.Part 2-4 on service provider security programs
- D.Part 2-3 on patch management in the IACS environment
Why D is correct
Part 2-3 is the patch management part, covering roles of owner, supplier and integrator in testing and deploying patches. The other parts address risk assessment, technology and service provider programs.
Know someone studying for OT Security Fundamentals? Send them this one.