Glossary · OT security engineering
Secure update
Also known as: Secure software update, Secure update process
German: Sichere Aktualisierung
In product security, a secure update is the end-to-end process of delivering software, firmware or configuration updates so that their authenticity, integrity and authorization are ensured from the manufacturer's build to installation on the device, and so that the update can be verified, documented and, if needed, reversed.
- Security engineering
- OT security
In one sentence
A secure update delivers software, firmware or configuration changes with ensured authenticity, integrity and authorization, from build to device.
Example
The vendor builds, signs and publishes an HMI update on its portal with a hash and advisory; the plant downloads it, verifies it, tests it on a reference panel and installs it under change control.
How it applies
- Product development: Secure updates need protected build systems and signing keys, signed packages, authenticated distribution channels and verification on the device. The Cyber Resilience Act (CRA) requires that vulnerabilities can be addressed through security updates and that these be provided for the support period.
- Operation: In OT, the operator decides when to install. Updates must therefore not install automatically on production systems without consent, and they should be separable into security and functional changes where possible.
- Maintenance: Change control and backups before the update, tests on a reference system and verification afterward belong to the process.
- Documentation: Documentation covers the update channel, how to verify packages, compatibility, required downtime, effects on configurations and certifications, and the reverse procedure. Keep release notes, manuals and the SBOM in step with each update.
Secure update vs. signed update
A Signed update is one mechanism. A secure update is the whole process, which also includes build security, distribution, authorization, testing and documentation.