1.1 This security evaluation standard applies to the evaluation of security and life safety signaling system components. It applies to, but is not limited to, the following products:
1.2 This standard does not contain general requirements that are intended to address functional testing of the product unless expressly specified.
1.3 This standard also describes requirements for the product risk management process carried out by the vendor of the product, including a list of security controls that the product (or the vendor, as applicable) shall comply with unless a risk assessment done by the vendor shows that the risk of not implementing one of these security controls is acceptable.
1.1 This security evaluation standard applies to the evaluation of security and life safety signaling system components. It applies to, but is not limited to, the following products:
1.2 This standard does not contain general requirements that are intended to address functional testing of the product unless expressly specified.
1.3 This standard also describes requirements for the product risk management process carried out by the vendor of the product, including a list of security controls that the product (or the vendor, as applicable) shall comply with unless a risk assessment done by the vendor shows that the risk of not implementing one of these security controls is acceptable.
| UL Standards & Engagement | |
|---|---|
| Product Category | Standards and Technical Documents |
| Product Number | UL 2900-2-3 |
| Product Name | Software Cybersecurity for Network-Connectable Products, Part 2-3: Particular Requirements for Security and Life Safety Signaling Systems |