Glossary · OT cybersecurity
Security development lifecycle (SDL)
Also known as: Secure development lifecycle, Secure product development lifecycle
German: Security Development Lifecycle (SDL)
In product development, a security development lifecycle (SDL) is a defined process that integrates security activities into every phase of developing and maintaining a product, from security requirements and threat modeling through secure design and implementation, testing, vulnerability handling and security updates. IEC 62443-4-1 specifies such a process for industrial automation products.
- OT security
- Standards
In one sentence
A security development lifecycle (SDL) builds security into every product development phase; IEC 62443-4-1 specifies it for automation products.
Example
Before release, the controller firmware passes the SDL gates: an updated threat model, code review of security-relevant modules, fuzz testing of the protocol stack and a completed security guideline.
Explained in context
Context cards connect this term with others to answer one question. Also in British English and German.
How it applies
- Product development: IEC 62443-4-1 groups its requirements into practices: security management, specification of security requirements, secure by design, secure implementation, security verification and validation testing, management of security-related issues, security update management, and security guidelines.
- Compliance: An SDL helps manufacturers meet the Cyber Resilience Act (CRA) essential requirements on secure design and vulnerability handling, but certification of the process alone does not establish product conformity.
- Maintenance: The lifecycle does not end at release: vulnerability handling and update delivery continue for the support period.
- Documentation: The security guidelines practice makes user documentation a formal deliverable: secure installation, configuration, operation, maintenance and decommissioning, plus the defense-in-depth assumptions. Documentation teams should be part of the SDL, not added at the end.
SDL vs. safety lifecycle
The Safety lifecycle of IEC 61508 manages activities to achieve functional safety. The SDL manages security activities. Many organizations align both so that changes are assessed for safety and security together.