Establishing an Industrial Automation and Control Systems Security Program Flashcards

1
Q

Whats means:

CSMS

A

Cyber Security Management System

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

CSMS Categories

A

Risk Analysis
Addressing Risk with the CSMS
Monitoring & Improving the CSMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How CSMS are organized?

A

Categories
Elements
Element Groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Risk Analysis

A

Includes business rationale along with risk identificacion, classification and assesment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Addressing Risk with CSMS

A

Includes security policy, organization & awarness along with security countermeasures and implementation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Monitoring & Improving CSMS

A

Includes conformance along with review, improvement and maintenance of CSMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

CSMS six top level activities

A
  • Initiate CSMS Program
  • Initial high level risk assessment
  • Detailed risk assessment
  • Establish policy, organization and awareness
  • Select and implement countermeasures
  • Maintain the CSMS
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Initiate CSMS Program

A
  • Develop a business rationale
  • Develop the CSMS Scope
  • Involve stakeholder(s)
  • Obtain leadership commitment, support and funding.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Initial High Level Risk Assessment

A
  • Drives the content of CSMS
  • Threats
  • Likelihood
  • Vulnerabilities
  • Consequences

Address risk assessment at a high level to reduce resources expenses and to establish an overall risk context

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Detailed risk Assessment

A
  • Detailed technical assessment
  • Focus on vulnerabilities identified at initial / high level
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Establish Policy, organization and awareness

A
  • Driven by initial/high-level and detailed risk assessment results
  • Creation of policies and procedures
  • Communicate policies
  • Assignment of organizational responsibilities
  • Planning and execution of training
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Select and implement countermeasures

A
  • Establish the risk tolerance
  • Select countermeasures
  • Implement countermeasures
  • Develop new or modify existing systems
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Maintain the CSMS

A
  • Is organization maturing in it CSMS activities?
  • Does organization conform to policies and procedures?
  • Are cyber security goals met effectively ?
  • Do the goals need to change in light of internal or external events?
  • Is a review of initial/high-level or detailed risk assessment required?
  • Are there improvements identified and implemented?
  • Are there training enhancements to make?
  • Has enthusiams and support waned?
  • Have other priorities pushed CSMS to the back burner?
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

True or False

Risk tolerance is determined by external, governing organizations

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

True or False

Detailed risk assesment should be conducted prior to a high-level risk assessment

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

True of False

CSMS includes 10 top level activities

A

False

CSMS include 6 top level activities

17
Q

True or False

The elements of the CSMS list the following; the objetive, the description, the rationale, and the requirements

A

True

18
Q

When initiating a CSMS program, why is it important to develop a business rationale first?

A

To help justify the program to management

19
Q

True or False

ISA 62443-2-1 contains a combination of SHOULD, MAY and SHALL requirements

A

TRUE

20
Q

What is the desired outcome of the initiate a CSMS program activity?

A

Obtain leadership commitment, support, and funding