iba AG places the highest importance on information security, as demonstrated by our certification according to ISO/IEC 27001:2022. In preparation for the legal requirements of the Cyber Resilience Act (CRA), iba AG is aligning its internal processes and products with internationally recognized standards such as IEC 62443-4-1 and IEC 62443-4-2. While we are first focusing on the requirements of CRA, these standards serve as a valuable framework to guide our structured and comprehensive implementation of CRA requirements.

Software Bill of Materials (SBOM)

As part of our commitment to transparency and software supply chain security, we generate Software Bills of Materials (SBOMs) in the CycloneDX format for all software products such as ibaPDA. These SBOMs can be reviewed by customers of iba AG as part of a supplier audit.

Product security

Product security is a top priority at iba AG. Throughout the entire product lifecycle, our solutions are continuously monitored for potentially exploitable vulnerabilities. Once a vulnerability is identified, we take immediate action to address it and ensure the ongoing security and reliability of our products.

Detailed information about topics like role-based access control, event logging or protocol security can be found in the respective product documentation.

Reporting security vulnerabilities

To provide our customers with a fast and straightforward way to report security vulnerabilities in iba AG products, we have established the dedicated email address psirt@iba-ag.com which enables direct communication with our Product Security Team.

Fixing security vulnerabilities

Every reported vulnerability is thoroughly examined and analyzed in collaboration with the responsible development team in order to develop a suitable solution. As soon as a fix is available, we will publish a detailed Security Advisory on our website. The customer who reported the vulnerability will also be notified via email once the advisory is released. The Security Advisory is available on our website at https://www.iba-ag.com/en/security and through our RSS feed.

If a permanent solution, such as a product patch, is not yet available at the time of the initial publication of the Security Advisory, it will be provided at a later stage. The patch will be made available in the iba download area for all customers. We will also announce its availability through an update to the Security Feed.

iba follows the response timelines defined in the Cyber Resilience Act when handling security reports.

Our goal during business hours is to

  • provide an initial assessment of the vulnerability within 24 hours

  • deliver a potential quick fix within 72 hours

  • implement a permanent fix in the affected product in a timely manner