In the office IT and operations OT areas, we test the interfaces between machines, management, office systems and to the internet. While doing so, it is irrelevant if the network is only operated inside a factory or if external communications partners such as branch offices are connected to this network over the internet. Testing also includes assessing the risk analysis related to information security as per IEC 62443. After a successful test, the network operator receives the VDE Certificate for information security.
The tested network is classified using a four-level scale. According to the existing IEC 62443 outlines, the use and certainty with which the attack is expected is described using this scale; they are called security levels (SL).
- Security Level 1: Protection against undesired, casual violation.
- Security Level 2: Protection against intentional violation using simple means with low resources, generic skills and low motivation.
- Security Level 3: Protection against intentional violation using sophisticated means with moderate resources, IACS-specific skills and moderate motivation.
- Security Level 4: Protection against intentional violation using sophisticated means with extended resources, IACS-specific skills and high motivation.
IEC 62443-4-1 lists requirements for the information security of development processes. We are happy to support you in implementing the development processes to ensure you are optimally prepared for the requirements of the CRA (Cyber Resilience Act).