← Home
IEC 62443-3-2 – Understand Risk
Understanding risk is the starting point for protecting an Industrial Automation and
Control System (IACS). Industrial cybersecurity is fundamentally
risk management: decide what matters, how it can fail under cyber attack,
and whether existing safeguards are good enough before spending on more controls.
You must understand the risk before you can manage it. The five approaches below are a
practical checklist that feeds the
Part 3-2 Clause 4
zone and conduit requirements (ZCRs).
Teaching note: Paraphrased for learning from IACS risk-assessment practice
and related ISA/IEC 62443 concepts. Not a verbatim extract of ISA publications or the
standard — always refer to published text for normative wording.
Related:
Cyber Risk Concepts
|
Develop a Plan
|
Benefits of a Risk Assessment
|
Criticality Assessment
|
Threats
|
Vulnerabilities
|
Consequence
|
Risk Equation
|
ZCR 2
|
ZCR 5
Five approaches to understanding risk
-
Identify the critical assets —
What must keep running for safety, environment, production and business continuity?
Criticality drives where assessment effort belongs.
See Criticality Assessment.
-
Determine the realistic threats —
Which threat sources and scenarios are credible for this plant and SuC — not every
theoretical attacker. See Threats.
-
Identify existing vulnerabilities —
Flaws or weaknesses in design, implementation or operation that a threat could exploit.
See Vulnerabilities.
-
Understand the consequence of compromise —
Worst-case effects on people, environment, property and business interruption if the
threat is realised. See Consequence.
-
Assess effectiveness of current safeguards —
What technical, administrative and physical controls already reduce likelihood or
impact — and how well do they work in practice? That judgement becomes residual-risk
input in detailed assessment
(mitigated likelihood).
How this maps into Part 3-2
- Initial assessment (ZCR 2) emphasises worst-case unmitigated exposure
for the whole SuC — especially health, safety and environment.
- Detailed assessment (ZCR 5) walks threats, vulnerabilities, consequence
and likelihood zone by zone (and conduit by conduit).
- The risk equation combines those
building blocks into scores the organisation can compare with
tolerable risk.
Key takeaways
- Cybersecurity for IACS is risk management, not a pure technology shopping list.
- Understand assets, threats, vulnerabilities, consequence and current safeguards
before treating risk.
- These five approaches orient the Clause 4 workflow; they do not replace the ZCRs.