← Home

IEC 62443-3-2 – Understand Risk

Understanding risk is the starting point for protecting an Industrial Automation and Control System (IACS). Industrial cybersecurity is fundamentally risk management: decide what matters, how it can fail under cyber attack, and whether existing safeguards are good enough before spending on more controls.

You must understand the risk before you can manage it. The five approaches below are a practical checklist that feeds the Part 3-2 Clause 4 zone and conduit requirements (ZCRs).

Teaching note: Paraphrased for learning from IACS risk-assessment practice and related ISA/IEC 62443 concepts. Not a verbatim extract of ISA publications or the standard — always refer to published text for normative wording.

Related: Cyber Risk Concepts | Develop a Plan | Benefits of a Risk Assessment | Criticality Assessment | Threats | Vulnerabilities | Consequence | Risk Equation | ZCR 2 | ZCR 5


Five approaches to understanding risk

  1. Identify the critical assets — What must keep running for safety, environment, production and business continuity? Criticality drives where assessment effort belongs. See Criticality Assessment.
  2. Determine the realistic threats — Which threat sources and scenarios are credible for this plant and SuC — not every theoretical attacker. See Threats.
  3. Identify existing vulnerabilities — Flaws or weaknesses in design, implementation or operation that a threat could exploit. See Vulnerabilities.
  4. Understand the consequence of compromise — Worst-case effects on people, environment, property and business interruption if the threat is realised. See Consequence.
  5. Assess effectiveness of current safeguards — What technical, administrative and physical controls already reduce likelihood or impact — and how well do they work in practice? That judgement becomes residual-risk input in detailed assessment (mitigated likelihood).

How this maps into Part 3-2


Key takeaways