SPECIALIST (MODULE 3) EXAM QUESTOPNS AND
ANSWERS WITH COMPLETE SOLUTIONS GRADED A++
MODELS
ASSET MODEL
REFERENCE ARCHITECTURE MODEL
ZONE MODEL
Reference models provide the overall conceptual basis for above 3 models
REFERENCD MODEL levels (ISA 95)
Five levels. Level0 to Level4
ISA 95 - Level4
business planning and logistics
ISA95 - Level3
Manufacturing Operations Management
ISA95 - Level2
Supervisory Control (monitoring and controling like temp control, pressure control)
ISA95 - Level1
Local or Basic Control (sensors, boiler, furnace...)
ISA95 - Level0
Actual production process or actual physical process
, The ISA-99 committee took
the ISA-95 Purdue model (Reference model)
IACS cybersecurity lifecycle
Assess, Develop and Implement, Maintain
Assess phase
Zones are assigned SL-T based on risk assessment
Develop and implement phase
countermeasures are applied to meet the SL-T
maintain phase
countermeasures are audited and/or tested and upgraded, if necessary, to reach and
maintain the SL-A
Assess phase in turn divided into (IC33 course)
Initial or high level risk assessment(part 3-2), Allocation of assets to zones or conduits
(part 3-2), Detailed risk assessment (part 3-2)
Develop and implement phase (IC 34 course)
1) Cybersecurity requirements specification(part 3-2),
2) the design and engineering of cybersecurity countermeasures(part 3-3) and
3) the installation, commissioning and validation of cybersecurity countermeasures (part
3-3)
Maintain phase (IC37 course)
1) cybersecurity countermeasures maintenance, monitoring, and change management
2) incident response and recovery
part 2-1 addresses this phase