0% found this document useful (0 votes)
6 views24 pages

IC33M Module Four Notes

The IC33 Module Four focuses on documentation and reporting in cybersecurity, emphasizing the importance of maintaining accurate records for assessments and risk management based on ISA 62443 standards. Key components include the Vulnerability Assessment Report, Cybersecurity Risk Assessment Report, and Cybersecurity Requirements Specification, all of which must be regularly updated to reflect changes in security conditions. The module outlines the necessity of documenting the threat environment and specific requirements for the System Under Consideration (SUC) to ensure comprehensive cybersecurity measures.

Uploaded by

shadowz
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views24 pages

IC33M Module Four Notes

The IC33 Module Four focuses on documentation and reporting in cybersecurity, emphasizing the importance of maintaining accurate records for assessments and risk management based on ISA 62443 standards. Key components include the Vulnerability Assessment Report, Cybersecurity Risk Assessment Report, and Cybersecurity Requirements Specification, all of which must be regularly updated to reflect changes in security conditions. The module outlines the necessity of documenting the threat environment and specific requirements for the System Under Consideration (SUC) to ensure comprehensive cybersecurity measures.

Uploaded by

shadowz
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

IC33M Module Four Notes

1.2 IC33 Module Four: Documentation and Reporting

Notes:

©2024 International Society of Automation


1.4 Course Learning Objectives

Notes:

The overall course goals are listed below. Take a moment to review these learning objectives which
are based on the ISA 62443 standards and industry best practices.

©2024 International Society of Automation


2.1 Documentation and Reporting

©2024 International Society of Automation


2.2 ZCR 5.13: Document and Communicate the Results

Notes:

There is a Cyber Mantra that states, "If you did not document it, you did not do it."
If you didn’t document your steps, there is nothing to verify, audit, or prove the assessment findings.
Documentation should be revised, amended, reviewed, and approved. Because it contains sensitive
security information, it should be under a control scheme.
All of these documents must be living documents. With every change in a zone, some of these
documents must be revised.
Risk assessments should be reviewed at least once a year.
Significant changes in the SUC or geopolitical situations should also trigger a review.
Can you think of some changes in the SUC that could require changes to documentation? (Pause)

New policies and procedures might lead to changes in the Initial Risk Assessment.
New NVD entries or vendor info might lead to changes in the Vulnerabilities report.
New vulnerabilities must be risk assessed.
New information on threads must be risk-assessed.
Like-for-like replacements lead to Asset Inventory changes with new MAC addresses and Firmware
versions.
Patches lead to changes in the Risk Assessment Report.

©2024 International Society of Automation


2.3 Vulnerability Assessment Report

The vulnerability assessment report should include the scope of the assessment and information
concerning the “as found” system architecture. Assessment details such as dates and location,
participants and the vulnerability process are noted. A prioritized summary of the findings should
be reported, including:
• Discovered cyber assets
• Policy & Procedural vulnerabilities
• Architecture & Design vulnerabilities
• Configuration & Maintenance vulnerabilities
• Physical vulnerabilities
• Software vulnerabilities and
• Communication & Network vulnerabilities

©2024 International Society of Automation


2.4 Cybersecurity Risk Assessment Report

The Cybersecurity Risk Assessment Report provides a risk profile.


As with other reports, always include the scope of the assessment and details concerning dates,
locations and participants.
The risk profile will document findings such as, high risk threats, high risk vulnerabilities, and
detailed risk assessment worksheets.
Be sure to document how you determined the likelihood and consequences.
Recommendations resulting for the risk assessment should be prioritized.

©2024 International Society of Automation


2.5 Cybersecurity Requirements Specification

Notes:

A Cybersecurity Requirements Specification (CRS) documents general security requirements based


upon company policy and standards, relevant regulations and the outcome of the high-level risk
assessment as well as any mandatory security functions of the SUC.

Grouping requirements can provide better organization of the information. For example, Access
Control requirements would include:
• Identification and authentication of users
• User roles and privileges, and
• User administration

Confidentiality, integrity and availability requirements may be logically grouped together, as well as
monitoring and reporting requirements.

The CRS should include:


• Scope and purpose of the system
• Physical and environmental security requirements
• General cybersecurity requirements
• Zone and Conduit specific requirements

Keep in mind, these are living documents which may change over time.

©2024 International Society of Automation


2.6 ZCR 6: Cybersecurity Requirements Specification

Notes:

Zone and Conduit Requirement 6 indicates, “A cybersecurity requirements specification (CRS) shall
be created to document mandatory security countermeasures of the SUC based on the outcome of
the detailed risk assessment as well as general security requirements based upon company or site-
specific policies, standards and relevant regulations.”

At a minimum you will need to include an SUC description,


Zone and conduit drawings,
Zone and conduit characteristics,
Operating environment assumptions,
Threat environment,
Organizational security policies,
Tolerable risk, and
Regulatory requirements.

It does not need to be in the form of a single document. Multiple documents such as Excel
spreadsheets, and even databases are frequently used. Remember to consider controlled access to
these.

©2024 International Society of Automation


2.7 ZCR 6: CRS

Notes:

The Cybersecurity Requirements Specification (CRS) is the input in the next step of the cybersecurity
lifecycle. It defines what needs to be done in the Develop & Implement phase. This is most likely
made up of multiple Excel documents or databases including assigned Target Security Levels (SL-T)
which need to be implemented.

©2024 International Society of Automation


2.8 SUC Description

Notes:

A high-level description and depiction of the System Under Consideration (SUC) is required as part
of the CRS.

This should include:


• Name
• High-level description
• Intended usage
• Architecture diagrams
• Network diagrams
• Security perimeter and Access points
• System inventory
• Dataflows and
• Process Flows

©2024 International Society of Automation


2.9 ZCR 6.4: Zone & Conduit Characteristics

Notes:

You will be required to provide detailed information for every zone and conduit. This is a large
amount of information. Carefully review the list to understand the requirements. Click on an
information marker to learn more about what should be included for specific characteristics.

©2024 International Society of Automation


2.10 Threat Environment

Notes:

You are required to document your Threat Environment as part of the CRS. This should include
threat sources, threat vectors, Geo-political environment and physical environment. Be sure to
indicate the source for threat intelligence such as the Cybersecurity & Infrastructure Security Agency
(CISA), the European Union Agency for Cybersecurity (ENISA), Local Government, IACS Product
suppliers, Anti-Malware vendors and Industry advisory groups.

©2024 International Society of Automation


3.1 Module Summary

Overlay Anim (Slide Layer)

©2024 International Society of Automation


3.2 Summary

Notes:

Take a moment to review what we have covered in this module by answering the following questions. You may
find it helpful to use the Menu on the left to revisit specific slides to review information.

©2024 International Society of Automation


3.3 Knowledge Check

©2024 International Society of Automation


3.4 Knowledge Check Q1

3.5 Review Q2

©2024 International Society of Automation


3.6 Review Q3

3.7 Review Q4

©2024 International Society of Automation


3.8 Review Q5

©2024 International Society of Automation


4.1 Module Four Quiz

©2024 International Society of Automation


©2024 International Society of Automation
3

©2024 International Society of Automation


5

©2024 International Society of Automation


4.5 ISA99 SharePoint Information

4.6 Certificate Exam

©2024 International Society of Automation


4.7 Course Survey

4.8 Thank you

©2024 International Society of Automation

You might also like