6. Introduction to the IACS Cybersecurity Lifecycle Flashcards
List THREE Stages of the IACS Cybersecurity Life Cycle
Assess
Develop and Implement
Maintain
Describe the Assess Phase
A zone is assigned a target security level (SL-T)
Describe the Develop and Implement Phase
Countermeasures are implemented to meet the target security level (SL-T)
Describe the Maintain Phase
Ensures the achieved security level (SL-A) is better or equal to the target security level (SL-T)
Countermeasures are audited/tested and upgraded if necessary to maintain (SL-A)
What THREE activities take place during the assess phase?
Initial/High Level Risk Assessment
Allocation of IACS assets to security zones and conduits
Detailed cyber risk assessment
What THREE activities take place during the Develop and Implement phase?
Requirements specification
Design and engineering of countermeasures
Installation comissioning and validation of countermeasures
What TWO activities take place during the maintain phase?
Cybersecurity maintenance monitoring, and management of change
Cyber incident response and recovery
Describe TWO continuous processes
Cybersecurity management sytstem: Policies, Procedures, Training & awareness
Periodic cybersecurity audits