A PLC vendor is asked by a customer to demonstrate that its development process meets IEC 62443-4-1. What does that part cover?
- A.Patch handling duties placed on the asset owner site team
- B.Secure product development lifecycle practices of the supplier
- C.Security program requirements for the contracted service providers
- D.System security requirements assigned to each security level
Why B is correct
Part 4-1 defines the secure development lifecycle a product supplier must follow. Service provider programs are 2-4, system level requirements are 3-3, and patch management is the subject of 2-3.
Know someone studying for OT Security Fundamentals? Send them this one.