ISA 62443 IC33 - All

0.0(0)
Studied by 13 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/187

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:23 PM on 3/12/25
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

188 Terms

1
New cards

What is the purpose of assigning a Target Security Level (SL-T) during the Assess phase of ICS security implementation?

To determine the existing vulnerabilities of the system.

2
New cards

What happens during the Develop & Implement phase of ICS security implementation?

Countermeasures are implemented to meet the Target Security Level (SL-T).

3
New cards

What is the primary goal of the Maintain phase in ICS security implementation?

To ensure the Achieved Security Level (SL-A) is equal to or better than the Target Security Level (SL-T).*

4
New cards

What is phase 1 of the IACS Cybersecurity Life Cycle?

Assess

5
New cards

What is phase 2 of the IACS Cybersecurity Life Cycle?

Develop & Implement

6
New cards

What is phase 3 of the IACS Cybersecurity Life Cycle?

Maintain phase

7
New cards

What is step 1 of the IACS Cybersecurity Life Cycle (Assess Phase)?

High-Level Cyber Risk Assessment

8
New cards

What is step 2 of the IACS Cybersecurity Life Cycle (Assess Phase)?

Allocation of IACS Assets to Security Zones or Conduits

9
New cards

What is step 3 of the IACS Cybersecurity Life Cycle (Assess Phase)?

Detail Cyber Risk Assessment

10
New cards

What is step 4 of the IACS Cybersecurity Life Cycle (Develop & Implement Phase)?

Cybersecurity Requirements Specification

11
New cards

What is step 5 of the IACS Cybersecurity Life Cycle (Develop & Implement Phase)?

Design and engineering of Cybersecurity countermeasures

12
New cards

What is step 6 of the IACS Cybersecurity Life Cycle (Develop & Implement Phase)?

Installation, commissioning and validation of Cybersecurity countermeasures

13
New cards

What is step 7 of the IACS Cybersecurity Life Cycle (Maintain)?

Cybersecurity Maintenance, Monitoring and Management of Change

14
New cards

What is step 8 of the IACS Cybersecurity Life Cycle (Maintain)?

Cyber Incident Response & Recovery

15
New cards

What are the continuous processes activities of the IACS Cybersecurity Life Cycle?

Cybersecurity Management System: Policies, Procedures, Training & Awareness, Periodic Cybersecurity Audits

16
New cards

What must be done before an assessment can be started?

Create a Project Plan

ID Steps of the Project to perform the assessment

ID the System Under Assessment

17
New cards

System Under Consideration (SUC)

The system or systems within an Industrial Automation and Control System environment that are being evaluated or designed for security enhancements.

18
New cards

System Under Assessment (SUA)

The system that is being evaluated for compliance with standards.

19
New cards

What are some required information gathering items before the assessment can begin?

Goals of the Assessment

IACS asset inventory

Understanding of the IACS

Regulations, requirements, and governance of relevance (Government, Industry, Company)

Architecture diagrams

Configuration Files

Known vulnerabilities

Define roles and responsibilities

Establish training requirements

20
New cards

System Architecture Diagrams

Depiction of system components, their connectivity, and physical locations.

21
New cards

Physical System Architecture Diagram

A diagram that provides a visual representation of the physical components within a system and their interconnections. It focuses on hardware elements such as servers, network devices, control systems, and terminals, showing how these components are arranged and connected.

22
New cards

Functional System Architecture Diagram

A diagram that describes the functions of a system and their relationships without focusing on physical details. It presents a logical view of the system, emphasizing software elements, data flows, and interactions between different functions or modules within the system.

23
New cards

(True/False) IACS functionality should be graphically represented on at least one IACS Architecture drawing

True

24
New cards

ISA-95 Functional Layer Level 0

The physical process — This level defines the physical processes showing data flowing from sensors and actuators into the control level.

25
New cards

ISA-95 Functional Layer Level 1

Intelligent devices — Devices in this level sense and manipule the physical processes. Process, sensors, analyzers, actuators and related instrumentation. This layer shows how PLCs receive field device data, process it, and then send commands back to the field devices.

26
New cards

ISA-95 Functional Layer Level 2

Control systems — Supervising, monitoring and controlling the physical processes. Real-time controls and software; DCS, human-machine interface (HMI); supervisory and data acquisition (SCADA) software. This level represents how the control systems manage PLCs, how operator commands are processed, and how alarm conditions are handled.

27
New cards

ISA-95 Functional Layer Level 3

Manufacturing operations systems — Managing production workflow to produce the desired products. Batch management; manufacturing execution/operations management systems (MES/MOMS); laboratory, maintenance and plant performance management systems; data historians and related middleware. Time frame: shifts, hours, minutes, seconds.

28
New cards

ISA-95 Functional Layer Level 4

Business logistics systems — Managing the business-related activities of the manufacturing operation. ERP is the primary system; establishes the basic plant production schedule, material use, shipping and inventory levels. Time frame: months, weeks, days, shifts. This level shows how enterprise systems deal with production planning and overall business logistics, and how this information is sent down to lower levels.

29
New cards

(True/False) ISA-95 functional layers are the same thing as the Purdue Enterprise Reference Architecture (PERA)

False

30
New cards

(True/False) ISA-95 functional layers speak to functionality - NOT systems or network layers.

True

31
New cards

ISA-95 Control Domain

Level 3, 2, 1, 0

32
New cards

ISA-95 Enterprise Domain

Level 4

33
New cards

What ISA-95 levels are critical to safety, reliability, efficiency, and quality

Levels 3, 2, 1, 0 (The Control Domain)

34
New cards

At a minimum, Network Diagrams should include...

Physical or Logical connections

Individual network devices represented symbollically

Switch port assignments

VLANs

Hosts (optional)

35
New cards

Host Device

Computing systems that host data or applications, such as servers, workstations, and user devices.

36
New cards

Embedded Devices

Computer systems with a dedicated function within IACS, like PLCs, RTUs, or IEDs.

37
New cards

Network Device

Components that facilitate data transmission within an IACS, including switches, routers, and firewalls.

38
New cards

Software Applications

Software systems used to control, monitor, or manage industrial processes, such as SCADA, HMI, MES, and ERP systems.

39
New cards

What is an Asset Inventory for IACS and SCADA Systems?

A list or database of all hardware (physical and virtual) and software within an IACS or SCADA environment, compiled through documentation and site surveys. Automated tools can be used for data gathering, but should be tested to avoid system impact or security vulnerabilities.

40
New cards

Why must automated tools for compiling an asset inventory in IACS and SCADA systems be carefully tested?

To ensure they do not impact system availability or integrity and do not introduce security vulnerabilities while gathering asset information.

41
New cards

What should the hardware asset inventory in an IACS should include?

Computers (e.g., servers, workstations), network equipment (e.g., switches, routers, firewalls), and automation devices (e.g., PLCs, DCSs, VFDs, RTUs).

42
New cards

What types of devices should be included in the hardware asset inventory in an IACS?

All devices with an Ethernet connection and an IP address, as well as devices with routable serial protocols like ControlNet, Profibus, Modbus TCP, etc.

43
New cards

What attributes of devices should be documented in an asset inventory?

Device or System Name

Asset ID

Device Type

Function

Network interface(s)

Network address(es)

Manufacturer

Model

Serial Number

Operating system and version (if applicable)

Firmware versions (if applicable)

Responsible organization/individual

Physical Location

Logging Features (if applicable)

Notes

44
New cards

What attributes of virtualized devices should be documented in an asset inventory?

VM name

VM Type

Function

Network interface(s)

Network address(es)

Host Name/ID

Host type

Operating system and version

Responsible organization/individual

Custodian(s) (Admin)

Logging Features

Notes

45
New cards

What categories of software should a software asset inventory include?

Operating systems

Applications

Databases

Firmware

46
New cards

What attributes of software devices should be documented in a software asset inventory?

Software Name

Software type (e.g. OS, application, database, firmware, etc.)

Function

Host Name

Host type (physical or virtual, server or workstation, network device, controller, etc.)

Vendor

Version

Responsible organization/person

License information

-# of Licenses

-Location of License

-License Expiration Date

Update/Patch Process

47
New cards

What are the three methods that should be used together to make a comprehensive asset inventory?

Document Analysis

Assisted Analysis with Tools

Plant Walk through

48
New cards

What is the risk equation?

Risk = Threat x Vulnerability

49
New cards

What is a threat source?

Person, group, or environment that can present a threat

50
New cards

What are common threat sources?

Authorized internal personnel

Authorized 3rd party

Unauthorized internal personnel

Unauthorized external person (hacker)

Malware

Equipment

Environment

Other

Any

51
New cards

What is a threat vector?

Potential medium that a threat source may leverage to compromise a zone or conduit

52
New cards

What is Spoofing?

Deliberate act to assume an identity in order to gain unauthorized access.

53
New cards

What is Tampering?

Unauthorized changes to a program, configuration, or data

54
New cards

What is Information Disclosure?

Unauthorized redirection of data

55
New cards

What is a Denial-of-Service attack?

Deny, degrade, or destroy access to data or resources

56
New cards

What is a Threat Catalog?

An organized list of potential threats to a system that includes information about the nature of each threat, related vulnerabilities, affected assets, potential impacts, and possible mitigation strategies. It's a crucial tool for risk management in IACS cybersecurity.

57
New cards

What ISA/IEC 62443 standard establishes criteria for threat sources and actions?

ISA/IEC-62443-3-2

58
New cards

Vulnerability

Any flaw or weakness in a system's design

59
New cards

(True/False) Vulnerability Analysis is the same thing as Cyber Risk Analysis.

False

60
New cards

(True/False) Not all vulnerabilities represent risk to an IACS network.

True

61
New cards

(True/False) All vulnerabilities lead to a consequence.

False

62
New cards

What are the types of Cybersecurity Vulnerability Assessments

High-level vulnerability assessment

Passive vulnerability assessment

Active vulnerability assessment

Penetration test (hunting for vulnerabilities)

63
New cards

What is a High-level Vulnerability assessment?

An evaluation of an organization's cybersecurity practices against industry standards and best practices, involving interviews, site walk-throughs, examination of configurations and documents, and policy reviews. Often referred to as a "Gap Assessment".

64
New cards

What is a Passive Cybersecurity Vulnerability Assessment?

A non-intrusive evaluation technique to discover network devices and vulnerabilities using methods like documentation review, system walk-throughs, traffic analysis, log collection, configuration review, and vulnerability database research. It aids in understanding the system, the industrial process, and helps in creating or updating documentation.

65
New cards

What is an Active Cybersecurity Vulnerability Assessment?

A proactive evaluation method to discover network devices and vulnerabilities using active network scanning tools like Nmap, Ping Sweep, and vulnerability scanners like OpenVAS, Nessus. It enhances the understanding of the system, the industrial process, and assists in creating or updating documentation.

66
New cards

What is Penetration Testing?

A method that starts with an active cybersecurity vulnerability assessment, simulates a malicious actor's perspective, and attempts to exploit known and unknown security vulnerabilities to validate the effectiveness of security countermeasures.

67
New cards

Conducting a High-Level Vulnerability Assessment

A process that involves identifying benchmark standards, gathering information via interviews, questionnaires, drawings, and site visits, comparing performance with benchmarks across people, processes, and technology, and documenting and reporting the results.

68
New cards

What is CSET (Cyber Security Evaluation Tool)?

A software tool by the U.S. Department of Homeland Security's ICS-CERT, designed to assist organizations in assessing their control systems and network security practices against recognized industry standards. It provides a systematic approach for evaluating cybersecurity posture.

69
New cards

What are some benefits of CSET?

CSET provides a repeatable and systematic approach for assessing cybersecurity posture, comparing it to industry standards, involving various organizational experts, identifying potential vulnerabilities in control systems and policies, and offering guidelines for IACS cybersecurity solutions and mitigations.

70
New cards

Policy Vulnerabilities

Weaknesses in established security policies that can include inadequate security objectives, weak access controls, or insufficient incident response procedures.

71
New cards

Procedural Vulnerabilities

Flaws in the implementation or execution of security procedures, such as improper change management, lack of security training, or neglecting regular security assessments.

72
New cards

Configuration & Maintenance Vulnerabilities

Weaknesses in the setup and ongoing management of industrial automation and control systems (IACS), including insecure configurations, improper maintenance practices, and lack of monitoring and control mechanisms.

73
New cards

Architecture & Design Vulnerabilities

Weaknesses or flaws in the foundational structure and conceptual design of industrial automation and control systems (IACS), including inadequate security considerations, flawed architecture choices, and insufficient protection mechanisms.

74
New cards

Configuration & Maintenance Vulnerabilities

Weaknesses in the setup and ongoing management of industrial automation and control systems (IACS), including insecure configurations, improper maintenance practices, and lack of monitoring and control mechanisms.

75
New cards

Physical Vulnerabilities

Weaknesses or susceptibilities in the physical aspects of industrial automation and control systems (IACS), including inadequate physical security measures, vulnerabilities in infrastructure, and potential threats from physical access.

76
New cards

Software Vulnerabilities

Weaknesses or flaws in software that can be exploited by attackers due to coding errors, design flaws, or insecure configurations. Addressing software vulnerabilities is crucial for maintaining the security and integrity of systems.

77
New cards

Communication & Network Vulnerabilities

Weaknesses or susceptibilities in the communication and networking components of industrial automation and control systems (IACS), including insecure protocols, inadequate segmentation, and lack of encryption. Addressing these vulnerabilities is crucial for maintaining secure and reliable communication within IACS.

78
New cards

Consequence

The undesirable result of an incident, usually described in terms of health and safety effects, environmental impacts, loss of property, and business interruption costs result that occurs from a particular incident

79
New cards

Impact

A measure of the ultimate loss or harm associated with a consequence. Impact may be expressed in terms of numbers of injuries and/or fatalities, extent of environmental damage and/or magnitude of losses such as property damage, material loss, loss of intellectual property, lost production, market share loss, and recovery costs.

80
New cards

Cyber Criticality Assessment

measuring the potential negative impact if information becomes unavailable, unreliable, or compromised. It communicates to employees/contractors and serves as an important input for risk assessment. It provides a methodology to identify worst-case consequences.

81
New cards

Simplified Risk Equation

Risk = Likelihood x Consequence

82
New cards

Full Risk Equation

Risk = Threat x Vulnerability x Consequence

83
New cards

Factors of Likelihood

Frequency and Probability

84
New cards

Risk Matrix

A tool used to assess and visualize risk in an IACS by classifying it based on the likelihood of a threat exploiting a vulnerability and the impact if it occurs. This helps prioritize mitigation efforts according to the risk level.

85
New cards

Vulnerability Assessment

A process of identifying, quantifying, and prioritizing system vulnerabilities. It uses various tools and techniques to identify potential weaknesses that need to be addressed, providing insights into the system's security gaps.

86
New cards

Risk Assessment

A broader process that identifies vulnerabilities, considers potential threats that might exploit these vulnerabilities, and the potential impact. It provides an understanding of the overall risk associated with vulnerabilities, guiding decisions on risk management and mitigation prioritization.

87
New cards

What is the difference between a cyber-incident and an intolerable consequence?

A cyber-incident refers to an event or action, malicious or not, that threatens the integrity, confidentiality, or availability of cyber systems. An intolerable consequence, on the other hand, is a result of a cyber-incident that exceeds an organization's predefined threshold of acceptable risk or impact, potentially causing significant harm to operations, safety, or reputation.

88
New cards

Understanding Cybersecurity Risk

The process of comprehending cybersecurity risk involves determining realistic threats, identifying existing vulnerabilities and critical assets, understanding the potential consequences of compromise, and assessing the effectiveness of current safeguards.

89
New cards

Developing a Plan to Address Unacceptable Risk

This involves evaluating existing countermeasures, recommending additional ones and changes to current policies, prioritizing recommendations based on relative risk, and assessing the balance between cost/complexity and effectiveness.

90
New cards

Benefits of Cyber Risk Assessments

Helps determine priority plants/processes, understand threats and vulnerabilities, intelligently design and apply countermeasures to reduce risk, prioritize activities and resources, and evaluate countermeasures based on their effectiveness versus cost/complexity.

91
New cards

Balancing Security and Cost

Perfect security is unaffordable. Thus, risk reduction is balanced against the cost of security measures intended to mitigate the risk.

92
New cards

4.2.3.1 Select a risk assessment methodology

The organization shall select a particular risk assessment and analysis approach and methodology that identifies and prioritizes risks based upon security threats, vulnerabilities and consequences related to their IACS assets.

93
New cards

4.2.3.2 Provide risk assessment background

Information

The organization should provide participants in the

risk assessment activity with appropriate

information including methodology training, before

beginning to identify the risks.

94
New cards

4.2.3.3 Conduct a high-level risk assessment

A high-level system risk assessment shall be performed to understand the financial and HS&E consequences in the event that availability, integrity, or confidentiality of the IACS is compromised.

95
New cards

4.2.3.4 Identify the industrial automation and control systems

The organization shall identify the various IACS, gather data about the devices to characterize the nature of the security risk, and group the devices into logically integrated systems.

96
New cards

Risk Identification, Classification, and Assessment

A systematic process to identify and assess the severity of IACS cyber risks an organization faces. It involves prioritizing and analyzing potential threats, vulnerabilities, and consequences. The objective is to guide cybersecurity investments to lower risk.

97
New cards

4.2.3.5 Develop simple network diagrams

The organization shall develop simple network diagrams for each of the logically integrated systems showing the major devices, network types, and general locations of the equipment.

98
New cards

4.2.3.6 Prioritize systems

The organization shall develop the criteria and assign a priority rating for mitigating the risk of each logical control system.

99
New cards

4.2.3.7 Perform a detailed vulnerability assessment

The organization shall perform a detailed vulnerability assessment of its individual logical IACS, which may be scoped based on the high-level risk assessment results and prioritization of IACS subject to these risks.

100
New cards

4.2.3.8 Identify a detailed risk assessment methodology

The organization's risk assessment methodology shall include methods for prioritizing detailed vulnerabilities identified in the detailed vulnerability assessment.