IC37 - IACS Cybersecurity Operations &
Maintenance | latest update
Save
Terms in this set (31)
Name the phases of the IACS (1) Assess Phase
cybersecurity lifecycle.
(2) Develop & Implement Phase
(3) Maintain Phase
What is the goal of the "Assess A zone is assigned a target security level (SL-T).
Phase"?
What is the goal of the "Develop & Countermeasure are implemented to meet the
Implement Phase"? target security level (SL-T).
What is the goal of the "Maintain Ensure the achieved security level (SL-A) is better
Phase"? than or equal to the target security level (SL-T).
Name the main activities performed (1) Cybersecurity Maintenance Monitoring and
within the "Maintain Phase"? Management of Change (ISA 62443-2-1)
(2) Cyber Incident Response & Recovery (ISA
62443-2-1)
, Name the continuous processes (1) Cyber Security Management System: Policies,
performed within the "Maintain Procedures, Training & Awareness (ISA 62443-2-1)
Phase"?
(2) Periodic Cybersecurity Audits (ISA 62443-2-1)
Explain the "4 Ts" of risk management. (1) Tolerate
(2) Transfer
(3) Terminate
(4) Treat
Explaint the meaning of "risk The risk is known (!) and accepted by the
tolerance". organization.
Explaint the meaning of "risk The risk is passed to a third party to manage.
transfer".
Note: This does not eliminate the risk.
Explaint the meaning of "risk The context of the risk (processes, site, system, etc.)
termination". is stopped entirely, hence the risk is no longer
relevant.
Explaint the meaning of "risk Aims to reduce either the likelihood or the resulting
treatment". impact, through introduction of relevant controls.
Maintenance | latest update
Save
Terms in this set (31)
Name the phases of the IACS (1) Assess Phase
cybersecurity lifecycle.
(2) Develop & Implement Phase
(3) Maintain Phase
What is the goal of the "Assess A zone is assigned a target security level (SL-T).
Phase"?
What is the goal of the "Develop & Countermeasure are implemented to meet the
Implement Phase"? target security level (SL-T).
What is the goal of the "Maintain Ensure the achieved security level (SL-A) is better
Phase"? than or equal to the target security level (SL-T).
Name the main activities performed (1) Cybersecurity Maintenance Monitoring and
within the "Maintain Phase"? Management of Change (ISA 62443-2-1)
(2) Cyber Incident Response & Recovery (ISA
62443-2-1)
, Name the continuous processes (1) Cyber Security Management System: Policies,
performed within the "Maintain Procedures, Training & Awareness (ISA 62443-2-1)
Phase"?
(2) Periodic Cybersecurity Audits (ISA 62443-2-1)
Explain the "4 Ts" of risk management. (1) Tolerate
(2) Transfer
(3) Terminate
(4) Treat
Explaint the meaning of "risk The risk is known (!) and accepted by the
tolerance". organization.
Explaint the meaning of "risk The risk is passed to a third party to manage.
transfer".
Note: This does not eliminate the risk.
Explaint the meaning of "risk The context of the risk (processes, site, system, etc.)
termination". is stopped entirely, hence the risk is no longer
relevant.
Explaint the meaning of "risk Aims to reduce either the likelihood or the resulting
treatment". impact, through introduction of relevant controls.