In this chapter, we will get into the details of risk assessments. We start by looking at the types of assessments that are out there. Next, we will explore the different approaches and techniques behind information technology system risk assessments, before we look at the added complexity of conducting Industrial control system—centric assessments. By the end of this chapter, you should have a good understanding of what is involved with conducting a variety of ICS-related risk assessment activities.
We will discuss the following topics:
- Attacks, objectives, and consequences
- Risk assessments
- A risk assessment example
- Security assessment tools