Establishing an Industrial Automation and Control Systems Security Program Flashcards
Whats means:
CSMS
Cyber Security Management System
CSMS Categories
Risk Analysis
Addressing Risk with the CSMS
Monitoring & Improving the CSMS
How CSMS are organized?
Categories
Elements
Element Groups
Risk Analysis
Includes business rationale along with risk identificacion, classification and assesment
Addressing Risk with CSMS
Includes security policy, organization & awarness along with security countermeasures and implementation
Monitoring & Improving CSMS
Includes conformance along with review, improvement and maintenance of CSMS
CSMS six top level activities
- Initiate CSMS Program
- Initial high level risk assessment
- Detailed risk assessment
- Establish policy, organization and awareness
- Select and implement countermeasures
- Maintain the CSMS
Initiate CSMS Program
- Develop a business rationale
- Develop the CSMS Scope
- Involve stakeholder(s)
- Obtain leadership commitment, support and funding.
Initial High Level Risk Assessment
- Drives the content of CSMS
- Threats
- Likelihood
- Vulnerabilities
- Consequences
Address risk assessment at a high level to reduce resources expenses and to establish an overall risk context
Detailed risk Assessment
- Detailed technical assessment
- Focus on vulnerabilities identified at initial / high level
Establish Policy, organization and awareness
- Driven by initial/high-level and detailed risk assessment results
- Creation of policies and procedures
- Communicate policies
- Assignment of organizational responsibilities
- Planning and execution of training
Select and implement countermeasures
- Establish the risk tolerance
- Select countermeasures
- Implement countermeasures
- Develop new or modify existing systems
Maintain the CSMS
- Is organization maturing in it CSMS activities?
- Does organization conform to policies and procedures?
- Are cyber security goals met effectively ?
- Do the goals need to change in light of internal or external events?
- Is a review of initial/high-level or detailed risk assessment required?
- Are there improvements identified and implemented?
- Are there training enhancements to make?
- Has enthusiams and support waned?
- Have other priorities pushed CSMS to the back burner?
True or False
Risk tolerance is determined by external, governing organizations
False
True or False
Detailed risk assesment should be conducted prior to a high-level risk assessment
False