IEC 62443-4-2
Security for industrial automation and control systems - Part 4-2: Technical security requirements for components
Overview
Specifies technical security requirements for components (embedded devices, host devices, network devices, and software applications) used in industrial automation and control systems.
Applicability
Technical security requirements for product components
Relevance to Cyber Resilience Act (CRA)
Essential for technical cybersecurity requirements and component-level security controls
Key Coverage Areas
Standard Sections & Chapters
Identification and authentication control
Use control
System integrity
Data confidentiality
Restricted data flow
Timely response to events
Resource availability
Related Cyber Resilience Act (CRA) Articles
Article I: ESSENTIAL CYBERSECURITY REQUIREMENTS
View Article →Comprehensive technical security requirements for all security domains
Implementation Guidance:
Implement all seven foundational requirements: authentication, access control, integrity, confidentiality, data flow restrictions, event response, and availability
Article 13: Obligations of manufacturers
View Article →Technical security requirements for product components
Implementation Guidance:
Apply security level targets (SL) and implement component security requirements
Quick Information
- Organization
- IEC
- Category
- Product Security
- Certification
- ✓ Available