← Home

IEC 62443-3-2 – Develop a Plan

When risk is above the organisation’s appetite, scoring alone is not enough. The asset owner needs a plan to address unacceptable risk: improve or add countermeasures, change policy and procedure, prioritise by relative risk, and weigh cost and complexity against effectiveness.

In Part 3-2 that plan shows up after comparisons with tolerable risk — at ZCR 4 (do we need detailed work?) and inside ZCR 5 (existing controls, residual risk, additional countermeasures). Programme-level policy for the same decisions sits in Part 2-1 ORG 2.1.

Teaching note: Paraphrased for learning from IACS risk-assessment practice and related ISA/IEC 62443 concepts. Not a verbatim extract of ISA publications or the standard — always refer to published text for normative wording.

Related: Understand Risk | Balancing Security vs Cost | Mitigated Likelihood and Residual Risk | Four Ts of Managing Risk | ZCR 5 | ZCR 6 – CRS | ZCR 7 – Approval | SP and Risk Assessment


Five steps for handling unacceptable risk

  1. Evaluate existing countermeasures — Technical, administrative and procedural controls already in place, and how effective they are. This is the heart of ZCR 5.8 and residual scoring.
  2. Recommend additional countermeasures — Where residual risk still exceeds tolerance, propose further controls (Part 3-3 system requirements with SL capability are a common catalogue).
  3. Recommend changes to current policies and procedures — Many gaps are not “missing boxes”; they are weak process. Programme elements in Part 2-1 often close those gaps.
  4. Prioritise recommendations (based upon relative risk) — Treat highest residual risk first; do not spread effort evenly across every finding.
  5. Evaluate cost / complexity versus effectiveness — Perfect security is unaffordable. See Balancing Security vs Cost.

Treatment choices — the Four Ts

When residual risk is still above tolerance, apply the Four Ts of managing risk: Tolerate (accept under policy), Transfer (e.g. insurance or contractual allocation), Terminate (remove the exposure), or Treat (more or better controls). Record the decision. Moving an asset into a higher-security zone can also borrow that zone’s countermeasures.

Where the choice is Treat, structure countermeasures with the Five Ds and zone/conduit strategy. Recommendations should be independently checked for unintended safety or cybersecurity side effects before implementation. Adjusted mitigated likelihood (MTLa) is sometimes recorded to show the expected improvement if recommendations are implemented — see Mitigated Likelihood and Residual Risk.


Key takeaways