0% found this document useful (0 votes)
26 views81 pages

IC33M Module Three Notes

The IC33M Module Three Notes provide an overview of navigating the course, emphasizing the importance of cyber risk assessments and risk management based on ISA 62443 standards. Key topics include understanding risk, developing a risk management plan, and the necessity of continuous improvement in cybersecurity practices. The document outlines the steps for conducting a detailed cybersecurity risk assessment, including identifying systems, threats, vulnerabilities, and determining security levels.

Uploaded by

shadowz
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
26 views81 pages

IC33M Module Three Notes

The IC33M Module Three Notes provide an overview of navigating the course, emphasizing the importance of cyber risk assessments and risk management based on ISA 62443 standards. Key topics include understanding risk, developing a risk management plan, and the necessity of continuous improvement in cybersecurity practices. The document outlines the steps for conducting a detailed cybersecurity risk assessment, including identifying systems, threats, vulnerabilities, and determining security levels.

Uploaded by

shadowz
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

IC33M Module Three Notes

1.2 IC33 Intro

Notes:

Audio (Slide Layer)

©2024 International Society of Automation


1.3 Instructions

Notes:

Let's take a minute to learn how to navigate this module.


Previous and Next buttons are found at the bottom right of the screen. Here you will also find the
Replay button and volume control.
On the bottom left, you will find the Play/Pause toggle.
The sidebar on the left, includes tabs for the Menu, Transcript and Resources.

©2024 International Society of Automation


1.4 Course Learning Objectives

Notes:

The overall course goals are listed below. Take a moment to review these learning objectives which
are based on the ISA 62443 standards and industry best practices.

©2024 International Society of Automation


2.1 Cyber Risk Assessments

2.2 Risk Management

Notes:

Understanding risk is fundamental to determining how to best protect our systems. Cybersecurity is
all about RISK MANAGEMENT.

©2024 International Society of Automation


2.3 Understanding Risk

Notes:

We must first understand the risk before we can manage it. Here are a few approaches to this
important part of a security program:

• Identify the critical assets


• Determine the realistic threats
• Identify existing vulnerabilities
• Understand the consequence of compromise
• Assess effectiveness of current safeguards

©2024 International Society of Automation


2.4 Develop a Plan

Notes:

How will your organization handle unacceptable risk? Develop a plan to address unacceptable risk.
Start with these suggestions:

• Evaluate existing countermeasures


• Recommend additional countermeasures
• Recommend changes to current policies and procedures
• Prioritize recommendations (based upon relative risk)
• Evaluate cost / complexity versus effectiveness

©2024 International Society of Automation


2.5 Benefits of Cyber Risk Assessments

Notes:

What are the benefits of cyber risk assessments?

Click each number to reveal advantages.

©2024 International Society of Automation


2.6 Balance

Notes:

Achieving the ideal security level is a balancing act.

We can’t afford perfect security.

Here the cost of security countermeasures is compared to the probable cost of security breaches.

Each organization must determine their own balancing point.

©2024 International Society of Automation


2.7 ISA/IEC 62443-2-1 Risk Assessment

Notes:

Risk assessment is not just a task; it's an essential component of the Cyber Security Management
System (CSMS). This process is all about maintaining continuous improvement in cybersecurity,
ensuring that defenses evolve and strengthen over time.
And remember, it’s the first step of the cybersecurity lifecycle, laying the groundwork for all the
protective measures that follow.
With a solid risk assessment, you're not just starting a process; you're fortifying the future of
cybersecurity. Anchoring the risk assessment within the broader CSMS, assures you take into
account changes in legislation, reorganizations within the organization, changes in risk management
methodologies, changes in technology like AI, assign sufficient resources to risk assessments, etc.

©2024 International Society of Automation


2.8 ISA 62443-2-1

Notes:

Let’s examine the elements and requirements for a Successful Program.


ELEMENT - Risk Identification, Classification, and Assessment
Objective: Identify the set of IACS cyber risks that an organization faces, and assess the severity of
these risks.
Description: Organizations protect their ability to perform their mission by systematically identifying,
prioritizing, and analyzing potential security threats, vulnerabilities, and consequences using
accepted methodologies.
Rationale: Since the purpose of cybersecurity investments is to lower risk, investment in
cybersecurity is driven by an understanding of level of risk.
ISA 62443-2-1 standard addresses Risk Assessment Requirements.
Click on each box to hear more about each requirement.

©2024 International Society of Automation


Layer 13 (Slide Layer)

Layer 12 (Slide Layer)

©2024 International Society of Automation


Layer 11 (Slide Layer)

Layer 10 (Slide Layer)

©2024 International Society of Automation


Layer 9 (Slide Layer)

Layer 8 (Slide Layer)

©2024 International Society of Automation


Layer 7 (Slide Layer)

Layer 6 (Slide Layer)

©2024 International Society of Automation


Layer 5 (Slide Layer)

Layer 4 (Slide Layer)

©2024 International Society of Automation


Layer 3 (Slide Layer)

Layer 2 (Slide Layer)

©2024 International Society of Automation


Layer 1 (Slide Layer)

©2024 International Society of Automation


3.1 Cyber Risk

©2024 International Society of Automation


3.2 Cyber Risk Assessment Process

Notes:

This flow chart outlines the cyber risk assessment process from ISA 62443-3-2. Let’s review the Zone
and Conduit requirements.

©2024 International Society of Automation


3.3 ZCR 1: Identify System Under Consideration (SUC)

Notes:

The first step in the assessment process is to identify the system under consideration or SUC
Initial System Architecture Diagrams and Inventory documents are used as references.
The SUC is often defined using a combination of illustrations and text. Clearly identify the assets
that are in-scope and identify the perimeter and all access points.
This step in the process provides an updated System Architecture Diagrams and Inventory
document.
Keep in mind that the SUC can include multiple subsystems.

©2024 International Society of Automation


©2024 International Society of Automation
3.4 ZCR 2: Initial Risk Assessment

Notes:

The next step is to conduct an initial risk assessment. This is an exercise to understand the worst
case financial and HS and E consequences in the event that the IACS has been compromised. Note
that a previous initial cybersecurity assessment may be used if it is confirmed as applicable.
Scope should include the entire system under assessment.
A team with knowledge of the industrial process develops worst case scenarios in which the control
system has been compromised.
If available, relevant Process Hazard Analysis (PHA) should be reviewed to help identify potential
consequences.

©2024 International Society of Automation


Layer 1 (Slide Layer)

©2024 International Society of Automation


3.5 ZCR 3.1: Establish Zones and Conduits

Notes:

Zones and conduits should be established to facilitate detailed cybersecurity risk assessment.

The assignment of IACS assets to zones and conduits may be adjusted based upon the results of the
detailed risk assessment.

Special attention should be given to:


• Safety Instrumented Systems (SIS)
• Wireless Systems
• Systems that interface to the IACS but are managed by other entities (including external systems)
and
• Mobile Devices

©2024 International Society of Automation


3.6 ZCR 3.2: Separate Business and IACS Assets

Notes:

Business and IACS are two different types of systems that need to be divided into separate zones.

Their functionality, responsible organization, results of high level risk assessment and location are
often fundamentally different.

It is important to understand the basic difference between business and control systems, which is
the ability of an IACS to impact health, safety and the environment.

©2024 International Society of Automation


3.7 System Architecture Diagram

Notes:

This is an example of an Architecture Diagram for an IACS showing equipment, locations and access
points. Click the button to see how this diagram should be labeled to identify zones and conduits.

©2024 International Society of Automation


zones (Slide Layer)

©2024 International Society of Automation


3.8 Exercise: Partition the SuC into Zones

Notes:

In this exercise you will be partitioning the system architecture diagram into zones.

Use drag and drop to place the zones in the correct place on the diagram.

©2024 International Society of Automation


3.9 ZCR 3.3: Separate Safety Related Assets

Notes:

Safety related IACS assets usually have different security requirements than basic control system
components or systems, and components interfaced to the control system components. Therefore,
they should be grouped into zones that are separate from zones with non-safety related assets. If
they cannot be separated, the entire zone should be identified as a safety zone.

©2024 International Society of Automation


3.10 ZCR 3.4: Separate Temporarily Connected Devices

Notes:

Devices such as maintenance laptops, portable processing equipment, portable security appliances,
and USB devices that are temporarily connected to the SuC are more likely exposed to different and
more varied threats than devices that are permanently part of the zone.

Therefore, these devices should be modeled in a separate zone. The primary concern is devices with
temporary connections, may also be able to connect to other networks outside the zone.

©2024 International Society of Automation


3.11 ZCR 3.5: Separate Wireless Communications

Notes:

Wireless communications should be in one or more zones that are separated from wired
communications because they are exposed to a wider variety of threats.

©2024 International Society of Automation


3.12 ZCR 3.6: Separate Devices Connected via External Networks

Notes:

Devices that are permitted to make connections to the SUC via external networks, such as remote
access, should be grouped into separate zones with its own security requirements.

©2024 International Society of Automation


3.13 ZCR 4: Compare Initial Risk to Tolerable Risk

Notes:

The initial cybersecurity risk assessment needs to be compared to the organization’s tolerable risk.
If the initial risk exceeds the tolerable risk, a detailed cybersecurity risk assessment is required. This
will be used to determine mitigation steps.

©2024 International Society of Automation


3.14 ZCR 5: Perform a Detailed Cybersecurity Risk Assessment

Notes:

This flow chart represents the detailed cyber risk assessment process as described in ISA 32443-3-2,
Section 5. Input documents are found on the left. The requirement is in the center and output
documents are on the left. This process must be conducted for every zone and conduit. Ahead, we
will go into more detail for each section.

©2024 International Society of Automation


3.15 Preparing for a Detailed Cybersecurity Risk Assessment

Notes:

There are 3 key tasks to consider when preparing for a detailed cybersecurity risk assessment.

First, Schedule a facilitator.

In order to ensure an effective Cyber Risk Assessment, the meetings should be facilitated by a
person who has a degree of independence from the design and operation of the control system,
control system networks and related IT systems and has received specialty training for leading Cyber
Risk Assessments.

Work with the facilitator to estimate the duration of the Cyber Risk Assessment.

©2024 International Society of Automation


Next, establish the team.

The team should include people with the right skills and attitudes that will result in the highest
quality assessment and recommendations. In general, the team should include:
• Facilitator trained in Cyber Risk Assessment
• Scribe trained in the software application to be used
• Automation/Controls Engineer(s)
• Network Engineer(s)
• Cybersecurity SME
• Process Safety SME
• Operator(s) with experience operating the process under consideration

©2024 International Society of Automation


Additionally, prepare workshop materials.

Required materials include:


• Network diagrams
• System architecture diagrams, and
• All previously conducted vulnerability assessments

Optional materials include:


• All previously conducted PHAs on the process(es) controlled by the system
• Data flow diagrams
• Control system inventory lists, and
• Process Flow Diagrams (PFDs)

©2024 International Society of Automation


3.16 ZCR 5.1: Identify Threats

Notes:

The Section 5.1 requirement includes providing a list of threats that could affect the assets
contained within the zone or conduit.
A good threat description should include:
• A description of the threat source
• A description of the capability or skill-level of the threat source
• A description of possible threat vectors
• Identification of the potentially affected asset(s)

Given the potential for many possible threats, it is acceptable to summarize by grouping sources,
assets, entry points, etc. into classes.

©2024 International Society of Automation


3.17 ZCR 5.2: Identify Vulnerabilities

Notes:

The next requirement for a detailed risk assessment is to identify vulnerabilities.

A vulnerability is any flaw or weakness in a system's design, implementation, or operation that could
be exploited to compromise the system.

In order for threats to be successful they must exploit one or more vulnerabilities in an asset.
Therefore, it is necessary to identify known vulnerabilities in assets to better understand threat
vectors.

©2024 International Society of Automation


Layer 1 (Slide Layer)

©2024 International Society of Automation


3.18 Vulnerability Considerations

Notes:

Access Points, Internal Networks and End Devices should be considered when identifying
vulnerabilities of an IACS. Asking the following questions can be helpful in the identification process.

What vulnerabilities exist that would allow an attacker or malware to pass through or circumvent
access controls at access points?

What vulnerabilities exist that would allow an attacker or malware to compromise the LAN(s) within
the zone?

What vulnerabilities exist at the end-devices (e.g. computers, industrial controllers, etc.) that would
allow an attacker or malware to compromise the device?

©2024 International Society of Automation


3.19 ZCR 5.3: Determine Consequence & Impact

Notes:

According to our standard, each threat identified shall be evaluated to determine the consequence
and the impact of the consequence should the threat be realized. Document impact in terms of the
worst-case impact on risk areas such as personnel safety, financial loss, business interruption, and
environment.

According to our standard, each threat identified in 5.1 and 5.2 shall be evaluated to determine the
consequence and the impact of the consequence should the threat be realized. Document impact
in terms of the worst-case impact on risk areas such as personnel safety, financial loss, business
interruption, and environment.

Consequence is the undesirable result of an incident, usually described in terms of health and safety
effects, environmental impacts, loss of property, and business interruption costs result that occurs
from a particular incident.

Estimating the worst-case impact of a cyber threat is an important input in performing the
cost/benefit analysis of security controls. If the worst-case impact is low, the risk assessment team
may decide to proceed to the next threat.

Existing PHA and other related risk assessments (such as, information technology, functional safety,
business and physical security) should be reviewed to assist in determining consequences and
impact.

©2024 International Society of Automation


3.20 ZCR 5.4: Determine Unmitigated Likelihood

Notes:

Determination of likelihood is an important step in determining risk. According to the requirement,


Each threat identified shall be evaluated to determine the likelihood that the threat will materialize.
The measure of likelihood may be quantitative, such as probability or it may be qualitative, such as
low, medium, or high.

Likelihood is influenced by several factors. One of these is Frequency. In other words, how often
does the threat arise? This can depend on the target’s attractiveness and the attack surface.

Probability is another factor. What is the likelihood that an attack will be successful? The answer
depends on the
capability of the threat actor, known vulnerabilities and the motivation or intent of the threat actor.

Likelihood is often evaluated twice during a detailed risk assessment. It is initially determined
without consideration of any existing countermeasures. This establishes the unmitigated risk. Later
in the process, it will be re-evaluated taking into account existing counter measures and their
effectiveness in order to determine residual risk.

©2024 International Society of Automation


3.21 Knowledge Check
(Drag and Drop, 10 points, 1 attempt permitted)

©2024 International Society of Automation


3.22 ZCR 5.5: Determine Unmitigated Cybersecurity Risk

Notes:

Determination of likelihood is an important step in determining risk. According to requirement 5.5,


Each threat identified shall be evaluated to determine the likelihood that the threat will materialize.
The measure of likelihood may be quantitative, such as probability or it may be qualitative, such as
low, medium, or high.

Likelihood is influenced by several factors. One of these is Frequency. In other words, how often
does the threat arise? This can depend on the target’s attractiveness and the attack surface.

Probability is another factor. What is the likelihood that an attack will be successful? The answer
depends on the
capability of the threat actor, known vulnerabilities and the motivation or intent of the threat actor.

Likelihood is often evaluated twice during a detailed risk assessment. It is initially determined
without consideration of any existing countermeasures. This establishes the unmitigated risk. Later
in the process, it will be re-evaluated taking into account existing counter measures and their
effectiveness in order to determine residual risk.

©2024 International Society of Automation


3.23 ZCR 5.6 Determine Security Level Target (SL-T)

Notes:

After determining risk, the next step is to determine the Security Level Target. A Security Level
Target shall be established for each security zone or conduit. SL-T is the desired level of security for
a particular IACS, zone or conduit. It is established to clearly communicate this information to those
responsible for designing, implementing, operating and maintaining cybersecurity. SL-T may be
expressed as a single value or a vector There is no prescribed method for establishing SL-T. Some
organizations chose to establish SL-T based upon the difference between the unmitigated
cybersecurity risk and tolerable risk.

©2024 International Society of Automation


3.24 Security Levels Defined

Notes:

ISA 62443-3-3 defines SLs in terms of five different levels (0, 1, 2, 3 and 4), each with an increasing
level of security. Take a moment to review the security levels before proceeding.

©2024 International Society of Automation


3.25 Types of Security Levels

Notes:

Three different types of Security Levels have been identified:


• Target,
• Achieved, and
• Capability

These types correspond to different aspects of the security lifecycle.

Click each Security Level Type to learn more.

©2024 International Society of Automation


Capability (Slide Layer)

Achieved (Slide Layer)

©2024 International Society of Automation


Target (Slide Layer)

©2024 International Society of Automation


3.26 Methods for Determining SL-T

Notes:

Various methods can be used to determine a target security level.

One method is to use your organization’s risk matrix. Here, a range of risk validates a certain SL-T.

©2024 International Society of Automation


3.27 ZCR 5.7: Compare Unmitigated Risk with Tolerable Risk

Notes:

The purpose of this step is to determine if the unmitigated risk is tolerable or if further evaluation is
required. The unmitigated risk was calculated using subclause 4.6.6, ZCR 5.5. If the unmitigated
risk exceeds the tolerable risk, the organization shall determine whether to accept, transfer or
mitigate the risk.

©2024 International Society of Automation


3.28 ZCR 5.8: Identify and Evaluate Existing Countermeasures

Notes:

The likelihood and impact need to be evaluated taking into account the presence and effectiveness
of existing countermeasures. This step in the process focuses on identifying and evaluating existing
countermeasures.

ISA 62443-3-3 provides guidance on types of countermeasures and their effectiveness by assigning a
security level capability (SL-C) to each system requirement.

The objective of most cybersecurity countermeasures is to reduce the likelihood by blocking threats
or reducing the attack surface. However, some countermeasures have the ability to mitigate the
severity of the consequence. For example, Ethernet rate limiting will prevent a device from crashing
due to network storms but will still result in a loss of view.

©2024 International Society of Automation


Layer 1 (Slide Layer)

©2024 International Society of Automation


3.29 Using Bowties to Visualize Threats and Countermeasures

Notes:

Ever wondered how industries keep a clear view of potential risks and their consequences? Enter the
bowtie diagram. Bowtie diagrams have been a reliable tool for many years across various industries.
They can be seen as a simplified version of a fault tree, but with unique strengths.
These diagrams help visualize several key aspects of risk, such as...
‘Threats’ and the countermeasures put in place to manage them. Sometimes, they even illustrate
how effective these countermeasures are.
The bowtie also highlights the risk source-the activity that could lead to damage if control is lost-and
outlines the potential consequences of such an event.
Beyond risk management, bowtie diagrams are also valuable for analyzing incidents, giving insights
into what happened and why.
So, whether planning or reviewing, these diagrams can play a key role in understanding and
managing risks."

©2024 International Society of Automation


3.30 Bowtie Diagrams

Notes:

The example Bowtie Diagram shows the following elements: Threats, Hazards, Top events, and
Consequences.

Threats are events that can lead to the top event; in the case of digital risks, these are typically
actions by attackers.

A hazard is an activity that an organization executes but that could cause damage if control is lost.

A top event is one during which control is lost: loss of confidentiality, integrity, or availability in the
case of digital security risks.

Consequences are the negative effects of the top event (related to our company's core values).

In the example, the first Threat is “Unauthorized WAN access.” This would potentially give the
attacker remote access to the Asset Owner's critical assets.

One of the hazards to this Asset Owner is SCADA commands to substation’. This is what the
automation in electricity of substations is all about monitoring the substation and, at the same time,
being able to send commands from the control center via the SCADA system to the substation to, for
example, open or close a breaker switch. But it also could cause trouble for the Asset Owner if this
function is lost. Technical personnel would need to be sent out to the substation to monitor and

©2024 International Society of Automation


operate it manually (in 24-7 shifts!!!).

The Top Event in the example is loss of integrity. This means that the Asset Owner can no longer
trust the values going to and coming from the substations. One consequence could be a (large)
electricity outage due to unauthorized switching.

©2024 International Society of Automation


3.31 Bowties and Control Barriers

Notes:

Control barriers play a crucial role in managing risks. But what exactly are they? Well, they are
proactive measures taken to minimize the likelihood of a significant event occurring.
The color of these barriers? It's not just for show. It tells us something important: the quality of the
measure-whether it’s strong and robust or needs attention.
But it doesn’t stop there. Barriers can also include recovery measures-like an intrusion detection
system that leaps into action or backups that help restore stability.
These elements come together to create a solid framework, one that aims to prevent top events and
prepares for a quick and efficient recovery if they do occur.

©2024 International Society of Automation


3.32 Bowties and Selecting Barriers

Notes:

Now that we know barriers are an important aspect of Bowties as they represent ways to reduce risk
(either the likelihood or the impact or both), we need to select the appropriate ones.

ISA/IEC-62443-3-3 can be used to select countermeasures, which are actually the barriers in the
Bowtie! On the left side, we have the control barriers, which try to prevent the threat from becoming
a reality. On the right side, we have the recovery barriers, which are there to reduce the impact of an
incident.
The tables in the example contain countermeasures from ISA/IEC-62443-3-3 that can be used for
both types of barriers: control and recovery.

©2024 International Society of Automation


3.33 ZCR 5.9: Re-evaluate Likelihood and Impact

Notes:

The likelihood and impact will need to be re-evaluated considering the countermeasures and their
effectiveness.

The unmitigated likelihood determined did not account for existing countermeasures. In this step,
countermeasures such as technical, administrative or procedural controls are considered and used
to determine mitigated likelihood. Likewise, the consequences and impact should also be re-
evaluated considering the identified countermeasures.

The Mitigated Threat Likelihood or MTL is the likelihood of the threat scenario occurring and leading
to the final consequence taking into account all protection measures and cybersecurity
countermeasures in place.

©2024 International Society of Automation


Layer 1 (Slide Layer)

©2024 International Society of Automation


3.34 ZCR 5.10: Determine Residual Risk

Notes:

The next requirement is to calculate the Residual Risk. The residual risk for each threat shall be
determined by combining the mitigated likelihood and impact measures.

Calculating residual risk provides a measure of the effectiveness of existing countermeasures. It is


an essential step in determining whether the level of unmitigated risk is at or below the tolerable
risk.

©2024 International Society of Automation


3.35 ZCR 5.11: Compare Residual Risk with Tolerable Risk

Notes:

The residual risk calculated for each threat 5.1 shall be compared to the organization’s tolerable risk
(specified in 4.4). If the residual risk exceeds the tolerable risk the organization shall determine if the
residual risk will be accepted, transferred or mitigated based upon the organization’s policy.

The purpose of this step is to determine if the residual risk is acceptable or requires further
mitigation.

If the residual cyber risk is above tolerable risk the team makes recommendations to further
investigate the risk ranking of a threat or to consider additional cybersecurity countermeasures.

When residual risk exceeds an organization's risk tolerance, steps must be taken to reduce the risk
to tolerable levels. Residual risk may be reduced, transferred or accepted.

©2024 International Society of Automation


3.36 ZCR 5.12: Apply Additional Security Countermeasures

Notes:

Additional cybersecurity countermeasures such as technical, administrative or procedural controls


shall be identified to mitigate the risks where the residual risk exceeds the organization’s tolerable
risk unless the organization has elected to tolerate or transfer the risk.

When residual risk exceeds an organization's risk tolerance, steps need to be taken to reduce the
risk to tolerable levels.

Countermeasures are applied to reduce risk. Cybersecurity countermeasures may be a combination


of technical and non-technical (such as, policies and procedures). Another means of reducing risk is
to reallocate an IACS asset from a lower security to a higher security zone or conduit in order to take
advantage of the security countermeasures of the higher security zone or conduit.

ISA-62443-3-3 can be used as a guide to select appropriate technical countermeasures. The


countermeasures identified in ISA-62443-3-3 have been assigned a SL-C rating which is beneficial in
evaluating the effectiveness of the countermeasure.

©2024 International Society of Automation


3.37 Recommendations and MTLa

Notes:

If the residual cyber risk is above tolerable risk the team makes recommendations to further
investigate the risk ranking of a threat or to consider additional cybersecurity countermeasures
The team records an Adjusted MTL (MTLa) to represent the anticipated decrease in likelihood of the
threat assuming implementation of the recommendations proposed by the team.
Any recommendations made by the team are expected to be independently evaluated to determine
any potential hazards or cybersecurity implications associated with the execution of the
recommended action.

©2024 International Society of Automation


3.38 ZCR 5.13: Document and Communicate Results

Notes:

The results of the detailed cyber risk assessment shall be documented, reported and made available
to the appropriate stakeholders in the organization. Appropriate information security classification
shall be assigned to protect the confidentiality of the documentation. Documentation shall include
the date each session was conducted as well as the names and titles of the participants.
Documentation that was instrumental in performing the cyber risk assessment (such as, system
architecture diagrams, PHAs, vulnerability assessments, gap assessments and sources of threat
information) shall be recorded and archived along with the cyber risk assessment.

Cybersecurity risk assessments need to be documented and made available to the appropriate
personnel in the organization. Cybersecurity risk assessments are living documents that may be
used for multiple purposes including testing, auditing and future risk assessments. However, it is
also important to properly protect this information as it often contains sensitive details about the
systems, known vulnerabilities and existing safeguards.

©2024 International Society of Automation


3.39 Recap: What are we doing?

Notes:

Let’s recap some important goals


We are Securing the SUC in a way that even if a cyber incident occurs and one or more components are
compromised the intolerable consequences won't happen.

For existing or brownfield systems, we are influencing the redesign of the plant (procedures, existing
SUC, and Assets) to make it resilient enough to any type of threat (natural, people, cyber).
For new or greenfield systems, we are influencing the design of the plant and the future SUC (with
procedures) to make it resilient enough from the very beginning.
In this module, we covered the risk assessment process as part of ISA/IEC 62443-2-1.
Keep in mind these are long-term decisions.

©2024 International Society of Automation


3.40 Summary

Notes:

©2024 International Society of Automation


3.41 Flash Card Review

Notes:
This is a flash card review. Each card includes a review question with the answer on the flip side. Click on the card to see the
answer. Click outside the card to see the front again. Click, next, to see another card.

©2024 International Society of Automation


Card 7 (Slide Layer)

©2024 International Society of Automation


Card 6 (Slide Layer)

©2024 International Society of Automation


Card 5 (Slide Layer)

©2024 International Society of Automation


Card 4 (Slide Layer)

©2024 International Society of Automation


Card 3 (Slide Layer)

©2024 International Society of Automation


Card 2 (Slide Layer)

©2024 International Society of Automation


Card 1 (Slide Layer)

©2024 International Society of Automation


4.1 Module Three Quiz

4.2 Module Three Quiz : Conducting Cybersecurity Assessments

Notes:

©2024 International Society of Automation


©2024 International Society of Automation
©2024 International Society of Automation
©2024 International Society of Automation
4.5 Thank you

Notes:

Thank you for completing Module One for Assessing the Cybersecurity of new and Existing IACS
Systems.

©2024 International Society of Automation

You might also like