Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT security engineering

Secure update

Also known as: Secure software update, Secure update process

German: Sichere Aktualisierung

In product security, a secure update is the end-to-end process of delivering software, firmware or configuration updates so that their authenticity, integrity and authorization are ensured from the manufacturer's build to installation on the device, and so that the update can be verified, documented and, if needed, reversed.

  • Security engineering
  • OT security

In one sentence

A secure update delivers software, firmware or configuration changes with ensured authenticity, integrity and authorization, from build to device.

Example

The vendor builds, signs and publishes an HMI update on its portal with a hash and advisory; the plant downloads it, verifies it, tests it on a reference panel and installs it under change control.

How it applies

  • Product development: Secure updates need protected build systems and signing keys, signed packages, authenticated distribution channels and verification on the device. The Cyber Resilience Act (CRA) requires that vulnerabilities can be addressed through security updates and that these be provided for the support period.
  • Operation: In OT, the operator decides when to install. Updates must therefore not install automatically on production systems without consent, and they should be separable into security and functional changes where possible.
  • Maintenance: Change control and backups before the update, tests on a reference system and verification afterward belong to the process.
  • Documentation: Documentation covers the update channel, how to verify packages, compatibility, required downtime, effects on configurations and certifications, and the reverse procedure. Keep release notes, manuals and the SBOM in step with each update.

Secure update vs. signed update

A Signed update is one mechanism. A secure update is the whole process, which also includes build security, distribution, authorization, testing and documentation.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Knowledge editorial definition, based on IEC 62443-4-1 and Regulation (EU) 2024/2847 (CRA)

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!