Glossary · Industrial cybersecurity
Update capability
In industrial systems, update capability is the technical and organizational ability to deliver, verify, document and, if needed, reverse updates to software, firmware and configuration, without compromising safety or the validity of evidence.
- Cybersecurity
- Compliance
In one sentence
Update capability is the ability to deliver, verify, document and if needed reverse updates to machine software and firmware safely.
Example
A conveyor controller verifies the signature of each firmware package, installs it only in a maintenance mode, keeps the previous version for rollback and records the new version in the machine’s logbook.
How it applies
- Technical: Authenticated update packages, integrity checks, defined installation states, rollback capability and version reporting. Updates of safety-related software may need additional protection and verification steps.
- Organizational: Who releases updates, how customers are informed, how long updates are provided and how installation is supported in the field.
- Compliance: The CRA requires that vulnerabilities can be addressed through security updates during the support period, and the Machinery Regulation requires records of safety software versions. Both assume update capability.
- Technical documentation: Release notes should state what changed in behavior, not only which bugs were fixed, so that operators and integrators can judge whether safety evidence is affected; see behavior version.
Update capability vs. patch management
Update capability is a property of the product and the organization. Patch management is the operator's and supplier's process for applying specific patches. A product without reliable update and rollback forces operators to choose between security and availability.