IC33M Module Four Notes
1.2 IC33 Module Four: Documentation and Reporting
Notes:
©2024 International Society of Automation
1.4 Course Learning Objectives
Notes:
The overall course goals are listed below. Take a moment to review these learning objectives which
are based on the ISA 62443 standards and industry best practices.
©2024 International Society of Automation
2.1 Documentation and Reporting
©2024 International Society of Automation
2.2 ZCR 5.13: Document and Communicate the Results
Notes:
There is a Cyber Mantra that states, "If you did not document it, you did not do it."
If you didn’t document your steps, there is nothing to verify, audit, or prove the assessment findings.
Documentation should be revised, amended, reviewed, and approved. Because it contains sensitive
security information, it should be under a control scheme.
All of these documents must be living documents. With every change in a zone, some of these
documents must be revised.
Risk assessments should be reviewed at least once a year.
Significant changes in the SUC or geopolitical situations should also trigger a review.
Can you think of some changes in the SUC that could require changes to documentation? (Pause)
New policies and procedures might lead to changes in the Initial Risk Assessment.
New NVD entries or vendor info might lead to changes in the Vulnerabilities report.
New vulnerabilities must be risk assessed.
New information on threads must be risk-assessed.
Like-for-like replacements lead to Asset Inventory changes with new MAC addresses and Firmware
versions.
Patches lead to changes in the Risk Assessment Report.
©2024 International Society of Automation
2.3 Vulnerability Assessment Report
The vulnerability assessment report should include the scope of the assessment and information
concerning the “as found” system architecture. Assessment details such as dates and location,
participants and the vulnerability process are noted. A prioritized summary of the findings should
be reported, including:
• Discovered cyber assets
• Policy & Procedural vulnerabilities
• Architecture & Design vulnerabilities
• Configuration & Maintenance vulnerabilities
• Physical vulnerabilities
• Software vulnerabilities and
• Communication & Network vulnerabilities
©2024 International Society of Automation
2.4 Cybersecurity Risk Assessment Report
The Cybersecurity Risk Assessment Report provides a risk profile.
As with other reports, always include the scope of the assessment and details concerning dates,
locations and participants.
The risk profile will document findings such as, high risk threats, high risk vulnerabilities, and
detailed risk assessment worksheets.
Be sure to document how you determined the likelihood and consequences.
Recommendations resulting for the risk assessment should be prioritized.
©2024 International Society of Automation
2.5 Cybersecurity Requirements Specification
Notes:
A Cybersecurity Requirements Specification (CRS) documents general security requirements based
upon company policy and standards, relevant regulations and the outcome of the high-level risk
assessment as well as any mandatory security functions of the SUC.
Grouping requirements can provide better organization of the information. For example, Access
Control requirements would include:
• Identification and authentication of users
• User roles and privileges, and
• User administration
Confidentiality, integrity and availability requirements may be logically grouped together, as well as
monitoring and reporting requirements.
The CRS should include:
• Scope and purpose of the system
• Physical and environmental security requirements
• General cybersecurity requirements
• Zone and Conduit specific requirements
Keep in mind, these are living documents which may change over time.
©2024 International Society of Automation
2.6 ZCR 6: Cybersecurity Requirements Specification
Notes:
Zone and Conduit Requirement 6 indicates, “A cybersecurity requirements specification (CRS) shall
be created to document mandatory security countermeasures of the SUC based on the outcome of
the detailed risk assessment as well as general security requirements based upon company or site-
specific policies, standards and relevant regulations.”
At a minimum you will need to include an SUC description,
Zone and conduit drawings,
Zone and conduit characteristics,
Operating environment assumptions,
Threat environment,
Organizational security policies,
Tolerable risk, and
Regulatory requirements.
It does not need to be in the form of a single document. Multiple documents such as Excel
spreadsheets, and even databases are frequently used. Remember to consider controlled access to
these.
©2024 International Society of Automation
2.7 ZCR 6: CRS
Notes:
The Cybersecurity Requirements Specification (CRS) is the input in the next step of the cybersecurity
lifecycle. It defines what needs to be done in the Develop & Implement phase. This is most likely
made up of multiple Excel documents or databases including assigned Target Security Levels (SL-T)
which need to be implemented.
©2024 International Society of Automation
2.8 SUC Description
Notes:
A high-level description and depiction of the System Under Consideration (SUC) is required as part
of the CRS.
This should include:
• Name
• High-level description
• Intended usage
• Architecture diagrams
• Network diagrams
• Security perimeter and Access points
• System inventory
• Dataflows and
• Process Flows
©2024 International Society of Automation
2.9 ZCR 6.4: Zone & Conduit Characteristics
Notes:
You will be required to provide detailed information for every zone and conduit. This is a large
amount of information. Carefully review the list to understand the requirements. Click on an
information marker to learn more about what should be included for specific characteristics.
©2024 International Society of Automation
2.10 Threat Environment
Notes:
You are required to document your Threat Environment as part of the CRS. This should include
threat sources, threat vectors, Geo-political environment and physical environment. Be sure to
indicate the source for threat intelligence such as the Cybersecurity & Infrastructure Security Agency
(CISA), the European Union Agency for Cybersecurity (ENISA), Local Government, IACS Product
suppliers, Anti-Malware vendors and Industry advisory groups.
©2024 International Society of Automation
3.1 Module Summary
Overlay Anim (Slide Layer)
©2024 International Society of Automation
3.2 Summary
Notes:
Take a moment to review what we have covered in this module by answering the following questions. You may
find it helpful to use the Menu on the left to revisit specific slides to review information.
©2024 International Society of Automation
3.3 Knowledge Check
©2024 International Society of Automation
3.4 Knowledge Check Q1
3.5 Review Q2
©2024 International Society of Automation
3.6 Review Q3
3.7 Review Q4
©2024 International Society of Automation
3.8 Review Q5
©2024 International Society of Automation
4.1 Module Four Quiz
©2024 International Society of Automation
©2024 International Society of Automation
3
©2024 International Society of Automation
5
©2024 International Society of Automation
4.5 ISA99 SharePoint Information
4.6 Certificate Exam
©2024 International Society of Automation
4.7 Course Survey
4.8 Thank you
©2024 International Society of Automation