Skip to content
Trausto

Methodology

Methodologies

Trausto is not a vertical. The same engineering discipline carries across regulated industries; what changes between them is the standard you have to answer to. Those are built in as first-class methodologies, not as a template retro-fitted onto a generic risk register.

Built in

In the product, not in an appendix

01

IEC 62443

Zones, conduits and trust boundaries are native objects, not custom columns in a GRC tool. SL-T targets sit on the zone, map to FR1–FR7 and export as evidence an assessor will recognise. Deriving SL-T normatively from the assessment is in development — today you set the target and the model records who set it.

02

ISO/IEC 27005

The information-security risk-management process end to end — context, identification, analysis, evaluation, treatment — running on the same asset and consequence model the 62443 work already uses. No second inventory to keep in sync.

03

ISO/IEC 27001 · Annex A

An ISMS register with the Statement-of-Applicability mechanism: applicability decisions, the justification for each one and the evidence attached to it — built for the audit conversation rather than for a spreadsheet. The Annex A control catalogue itself is in preparation; ask us where it stands before you plan around it.

04

EN 50701

The railway adaptation of the 62443 method, selectable per project: rail step labels throughout, and likelihood derived from exposure × vulnerability. The 5×5 matrix behind that derivation ships as readable configuration, not as hidden code — you can check the arithmetic and disagree with it, which is the part an assessor actually asks about.

Position

Why there are no industry pages

Sector labels sell well and survive no real assessment. A substation, a filling line and an interlocking differ in consequence and constraint, not in method. We would rather be exact about the standard you are audited against than list four industries and mean the same thing four times.

Zones & conduits · SL-T derivation · FR1–FR7 · Consequence-driven risk · Safety impact · Criticality · Statement of Applicability · Control evidence · Supplier evidence · Threat scenarios · Audit-ready exports.

See Trausto against your own zones

Bring one real site — your zones, conduits and SL-T targets. In a single technical session we show how Trausto turns it into audit-ready IEC 62443 evidence, with your assessment content encrypted before it ever leaves the browser.