Re: CIP Security Image – Improve Security T esting for continued IEC 62443-4-2 Compliance
| Newsgroups | org.cip-project.lists.cip-dev |
|---|---|
| Message-ID | <TYCPR01MB8819E7E94887C98A2698F20EC4E82@TYCPR01MB8819.jpnprd01.prod.outlook.com> |
Hi All, Just a gentle reminder. Any thoughts / feedback on this topic would be much appreciated. Thanks and Regards, Adithya Balakumar ________________________________ From: [email protected] <[email protected]> on behalf of Adithya Balakumar <[email protected]> Sent: Tuesday, June 23, 2026 9:28 AM To: [email protected] <[email protected]> Cc: [email protected] <[email protected]>; dinesh kumar(TSIP DITC_DIT-OST) <[email protected]>; [email protected] <[email protected]> Subject: [cip-dev] CIP Security Image – Improve Security Testing for continued IEC 62443-4-2 Compliance Hi All, As part of our ongoing efforts to improve security testing and maintain IEC 62443-4-2 compliance following the BV certification assessment, the CIP SWG would like to share the current plans and open discussion points around running security tests in the CIP security image. Background: During the IEC 62443-4-2 assessment, the certification body (BV) used several tools as part of the SVV-3 (Vulnerability Testing) and SVV-4 (Penetration Testing) activities. Building on this, the CIP SWG plans to integrate checksec [1] and lynis [2] into the CIP security image and run OpenVAS [3] scans to proactively identify vulnerabilities. The details of the kind of tests run by each of the tools mentioned above are briefly explained in the attached document. Current Plans: • Include checksec and lynis in the CIP security image to generate audit reports. • Run security scans using OpenVAS (comparable to Nessus) to identify vulnerabilities in the image. • Automate these tests via the isar-cip-core CI pipeline. Dependencies: • checksec and lynis to be installed in the security image via test extensions. • OpenVAS service to be deployed in the CIP infrastructure for CI-based testing. Goals: • Maintain compliance with IEC 62443-4-2 security test requirements. • Investigate and report discovered issues, and collaborate with the respective package maintainers to address them. Open Discussion Points - We would appreciate input on the following: 1. Frequency of test runs – Scans be triggered for every release tag. 2. Report storage – How and where should CI-generated reports be stored and retained? 3. OpenVAS deployment – Running OpenVAS as a service in the CIP test infrastructure. Please share your thoughts and any concerns at your earliest convenience. [1] https://github.com/slimm609/checksec [2] https://github.com/cisofy/lynis [3] https://github.com/greenbone/openvas-scanner Best regards, Adithya Balakumar