Criticality assessment rates how severe the negative impact would be if an IACS asset’s information or function were unavailable, unreliable or compromised. It supports the initial / high-level cybersecurity risk view in Part 3-2 (ZCR 2) and later appears in zone/conduit characteristics (ZCR 6.4 records assets with classification, criticality and business value).
Reference: ISA/IEC 62443-3-2:2020 (Clauses 4.3 and 4.7.5)
Related:
Cyber Risk Concepts
|
Consequence
|
Risk Equation
|
ZCR 2 – Initial Risk
|
ZCR 3 – Zones and Conduits
|
ZCR 6 – CRS
Criticality answers: if this asset is interfered with, which consequences matter most? It is not a full threat catalog. It helps prioritise partitioning (ZCR 3), decide whether detailed assessment is warranted (ZCR 4), and document asset importance in the CRS.
Use and develop evidence from:
Those same inputs inform worst-case unmitigated impact in ZCR 2 and consequence scoring in ZCR 5.3 — keep one narrative of “what goes wrong” rather than inventing a second scale. See Consequence.
A practical method used with Part 3-2 initial risk thinking is to walk each asset (or logical grouping) through Availability, Integrity and Confidentiality:
| Property | Question |
|---|---|
| Availability | Assume availability is compromised — what are the consequences? |
| Integrity | Assume integrity is compromised — what are the consequences? |
| Confidentiality | Assume confidentiality is compromised — what are the consequences? |
Assign a criticality rating per asset from those answers and record the list. In OT, availability and integrity usually dominate; confidentiality still matters for recipes, formulations, intellectual property and remote-access credentials.