Re: CIP Security Image – Improve Security T esting for continued IEC 62443-4-2 Compliance

<[email protected]>
Newsgroups org.cip-project.lists.cip-dev
Message-ID <TYCPR01MB8819E7E94887C98A2698F20EC4E82@TYCPR01MB8819.jpnprd01.prod.outlook.com>
Hi All,

Just a gentle reminder. Any thoughts / feedback on this topic would be much appreciated.

Thanks and Regards,
Adithya Balakumar
________________________________
From: [email protected] <[email protected]> on behalf of Adithya Balakumar <[email protected]>
Sent: Tuesday, June 23, 2026 9:28 AM
To: [email protected] <[email protected]>
Cc: [email protected] <[email protected]>; dinesh kumar(TSIP DITC_DIT-OST) <[email protected]>; [email protected] <[email protected]>
Subject: [cip-dev] CIP Security Image – Improve Security Testing for continued IEC 62443-4-2 Compliance

Hi All,

As part of our ongoing efforts to improve security testing and maintain IEC 62443-4-2 compliance following the BV certification assessment, the CIP SWG would like to share the current plans and open discussion points around running security tests in the CIP security image.

Background:
During the IEC 62443-4-2 assessment, the certification body (BV) used several tools as part of the SVV-3 (Vulnerability Testing) and SVV-4 (Penetration Testing) activities. Building on this, the CIP SWG plans to integrate checksec [1] and lynis [2] into the CIP security image and run OpenVAS [3] scans to proactively identify vulnerabilities.

The details of the kind of tests run by each of the tools mentioned above are briefly explained in the attached document.

Current Plans:
• Include checksec and lynis in the CIP security image to generate audit reports.
• Run security scans using OpenVAS (comparable to Nessus) to identify vulnerabilities in the image.
• Automate these tests via the isar-cip-core CI pipeline.

Dependencies:
• checksec and lynis to be installed in the security image via test extensions.
• OpenVAS service to be deployed in the CIP infrastructure for CI-based testing.

Goals:
• Maintain compliance with IEC 62443-4-2 security test requirements.
• Investigate and report discovered issues, and collaborate with the respective package maintainers to address them.

Open Discussion Points - We would appreciate input on the following:
1. Frequency of test runs – Scans be triggered for every release tag.
2. Report storage – How and where should CI-generated reports be stored and retained?
3. OpenVAS deployment – Running OpenVAS as a service in the CIP test infrastructure.

Please share your thoughts and any concerns at your earliest convenience.

[1] https://github.com/slimm609/checksec
[2] https://github.com/cisofy/lynis
[3] https://github.com/greenbone/openvas-scanner

Best regards,
Adithya Balakumar
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.