Conducting risk assessments in SISs
For the context of SISs, we will highlight how a risk assessment is conducted with a focus on IEC 62443, NAMUR, and BowTie as widely adopted standards in process industries.
IEC 62443-3-2
The IEC 62443-3-2 standard utilizes a qualitative approach to cyber risk assessment aimed at identifying the potential for cyber attacks that could lead to incidents harming human life, the environment, property, or operational capabilities. A detailed summary of this methodology is provided in the following diagram:
Figure 6.3 – Diagram depicting the HAZOP method for risk assessment based on the IEC 62443-3-2 standard
As per Figure 6.3, the steps taken for the high-level risk assessment were the following:
- Identify/select systems under consideration (SuCs): This step is about defining the scope of the risk assessment. It involves identifying SISs and other ICSs that will be assessed.
- Identify threats and vulnerabilities...