Documentation
ISA/IEC 62443 Compliance Tracker - an Atlassian Forge app by The Bent Spatula.
You need your own licensed copy of ISA/IEC 62443-3-3. This app is a tracking tool. It uses requirement identifiers and titles only, the titles with ISA's approval; it does not reproduce the text of the standard, which is copyrighted by ISA/IEC.
ISA/IEC 62443 is published by ISA/IEC. This app is not affiliated with, endorsed by, or certified by IEC, ISA or ISASecure.
Everything is labelled by identifier and title. A ticket is called
SR 1.1 - Human user identification and authentication, an epic
FR 1 - Identification and Authentication Control. The titles are used with ISA's
approval; the requirement wording itself is not reproduced, so each ticket and guide page asks
you to paste the text from your own licensed copy.
You get the structure, the Security Level scoping and the tracking. The standard's content stays with the standard.
What it does
Creates a requirement backlog in a Jira project you choose: one epic per Foundational Requirement (FR), one ticket per System Requirement (SR), and one ticket per Requirement Enhancement (RE) that your target Security Level requires — each enhancement linked to the requirement it enhances. Optionally adds a Confluence implementation-guide page per requirement, linked to its ticket. A project page then reports progress across all of them.
Getting started
- Install the app, then open Apps → ISA/IEC 62443 Compliance Tracker in Jira.
- Pick the Jira project to generate into.
- Pick your target Security Level (SL1–SL4).
- Pick the issue types to use for epics and for requirements. The app reads these from your project rather than assuming "Epic" and "Story", so the names you see are your project's own.
- Optionally tick Confluence implementation guides and choose a space.
- Tick the licensed-copy acknowledgement, then choose Create.
Work is batched, retries on rate limiting, and can be re-run safely if it stops partway.
What Security Level actually changes
The Security Level determines both which of the 51 System Requirements apply and which Requirement Enhancements they carry. 38 requirements apply at SL1, 49 at SL2, and all 51 from SL3. Each enhancement in scope becomes its own ticket, linked to the requirement it enhances.
| Target | Epics | Requirement tickets | Enhancement tickets | Total issues | Guide pages |
|---|---|---|---|---|---|
| SL1 | 7 | 38 | 0 | 45 | 46 |
| SL2 | 7 | 49 | 11 | 67 | 57 |
| SL3 | 7 | 51 | 39 | 97 | 59 |
| SL4 | 7 | 51 | 49 | 107 | 59 |
Each enhancement ticket carries an SL2, SL3 or SL4
label for the level that first requires it. That, and which tickets exist, is the record of the
level a project is working to — no target level is written into requirement descriptions,
because those are never rewritten and would go stale.
The project page turns this into a scoreboard: the target level (derived from the tickets present) alongside the achieved level, which is the highest level where every requirement and enhancement it demands is Done.
Re-running
Every issue carries a stable label (IEC62443-SR-1-1,
IEC62443-SR-1-1-RE-1 and so on). Re-running detects those and skips them, so nothing
is duplicated and an interrupted run can simply be run again.
Raising the Security Level later adds only what that level introduces. Run at SL2 today and SL4 next quarter, and the second run creates just the enhancements SL3 and SL4 require — every existing ticket is left exactly as it is.
Lowering the level does nothing: the app never deletes an issue it created, so enhancements for higher levels stay until you remove them yourself. The app warns you when it detects this.
Confluence guides
Guide pages are stubs for your team to complete: sections for the requirement text, approach, controls, verification and evidence. They carry requirement identifiers and titles only — no requirement text from the standard, and no guidance on it.
The app never deletes a page, and rewrites only one part of one. Pages are matched by title; anything already there is kept. The single exception is the Requirement enhancements in scope section, which the app maintains so that raising your Security Level keeps it accurate. Everything else on the page is yours and is never touched.
That section is delimited by invisible anchors. If you edit inside it, or remove the anchors, the app stops updating that page and tells you so — it will not overwrite your changes. Put your own notes outside the section to keep it maintained. To regenerate a page from scratch, delete it in Confluence and re-run.
Permissions and data
The app runs entirely on Atlassian infrastructure (Forge). No data leaves your Atlassian instance, it calls no external services, and it stores nothing - not even in Forge storage. All state lives in the Jira issues and Confluence pages it creates in your own site.
| Scope | Why |
|---|---|
read:jira-work | List projects, read issue types and required fields, and find already-created requirements so they are skipped |
write:jira-work | Create the epics and tickets, link each ticket to its guide page, and link each enhancement to the requirement it enhances |
read:space:confluence | List spaces you can generate guides into |
read:page:confluence | Detect guide pages that already exist |
write:page:confluence | Create the guide pages |
There is no user-directory permission. The app never reads a user record, and every issue it creates is unassigned for your team to pick up as normal.
Before you rely on it
Verify the requirement-enhancement-to-Security-Level mappings against your licensed copy of ISA/IEC 62443-3-3 before treating the generated scope as compliance evidence. The app scaffolds and tracks work; you and your auditors determine compliance.
Support
Email support@thebentspatula.com. This is a free app maintained outside business hours: expect acknowledgement within two business days. There is no guaranteed resolution time, and no phone or live-chat support.
When reporting a problem, include your Jira project key, the target Security Level you chose, and the message shown in the app - that is usually enough to identify the cause.
Links
This app uses ISA/IEC 62443 requirement identifiers and the standard's structural scheme. It reproduces no text from ISA/IEC 62443 — not the requirement text, not the requirement titles. You need your own licensed copy of the standard.