COMPLETE QUESTIONS AND
CORRECT DETAILED ANSWERS
(VERIFIED ANSWERS) A+ GRADED
ck
lo
yc
ud
St
,What is the purpose of assigning a Target Security Level (SL-T) during the Assess phase of ICS
security implementation?
To determine the existing vulnerabilities of the system.
What happens during the Develop & Implement phase of ICS security implementation?
Countermeasures are implemented to meet the Target Security Level (SL-T).
What is the primary goal of the Maintain phase in ICS security implementation?
To ensure the Achieved Security Level (SL-A) is equal to or better than the Target Security Level
(SL-T).*
ck
What is phase 1 of the IACS Cybersecurity Life Cycle?
Assess
lo
What is phase 2 of the IACS Cybersecurity Life Cycle?
Develop & Implement
yc
What is phase 3 of the IACS Cybersecurity Life Cycle?
Maintain phase
What is step 1 of the IACS Cybersecurity Life Cycle (Assess Phase)?
ud
High-Level Cyber Risk Assessment
What is step 2 of the IACS Cybersecurity Life Cycle (Assess Phase)?
Allocation of IACS Assets to Security Zones or Conduits
St
What is step 3 of the IACS Cybersecurity Life Cycle (Assess Phase)?
Detail Cyber Risk Assessment
What is step 4 of the IACS Cybersecurity Life Cycle (Develop & Implement Phase)?
Cybersecurity Requirements Specification
What is step 5 of the IACS Cybersecurity Life Cycle (Develop & Implement Phase)?
Design and engineering of Cybersecurity countermeasures
, What is step 6 of the IACS Cybersecurity Life Cycle (Develop & Implement Phase)?
Installation, commissioning and validation of Cybersecurity countermeasures
What is step 7 of the IACS Cybersecurity Life Cycle (Maintain)?
Cybersecurity Maintenance, Monitoring and Management of Change
What is step 8 of the IACS Cybersecurity Life Cycle (Maintain)?
Cyber Incident Response & Recovery
ck
What are the continuous processes activities of the IACS Cybersecurity Life Cycle?
Cybersecurity Management System: Policies, Procedures, Training & Awareness, Periodic
Cybersecurity Audits
lo
What must be done before an assessment can be started?
Create a Project Plan
yc
ID Steps of the Project to perform the assessment
ID the System Under Assessment
System Under Consideration (SUC)
The system or systems within an Industrial Automation and Control System environment that
ud
are being evaluated or designed for security enhancements.
System Under Assessment (SUA)
The system that is being evaluated for compliance with standards.
St
What are some required information gathering items before the assessment can begin?
Goals of the Assessment
IACS asset inventory
Understanding of the IACS
Regulations, requirements, and governance of relevance (Government, Industry, Company)
Architecture diagrams
Configuration Files
Known vulnerabilities
Define roles and responsibilities
Establish training requirements