Quillnet
Standards
CRA - Manufacturer
IEC-62443-2-1
IEC-62443-4-1
6.3.2: Processes For Discovery Of Security Anomalies
Mandatory
Requirement:
The asset owner shall have policies and procedures related to periodically discovering and addressing, through manual or automated processes: a) undocumented and unauthorized components/software connected to or communicating within the IACS, b) undocumented and/or unauthorized network traffic, c) new and/or known but undocumented vulnerabilities in the IACS, and d) other security anomalies and non-conformities.
Guidance: