QUESTIONS AND ANSWERS, GRADED A+
If you didn't document it - ✅✅-it didn't happen
What "shall" be done with documentation created? - ✅✅-It shall be revised, amended, reviewed,
approved, and under a control scheme.
What should be included in a Vulnerability Assessment Report? - ✅✅-Scope of the assessment
"As found" system architecture
Assessment details
-Dates/Locations
-Participants
-Vulnerability Assessment Process
Prioritized summary of findings
Detailed findings
-Discovered cyber assets
-Policy & Procedural vulnerabilities
-Architecture & Design vulnerabilities
-Configuration & Maintenance vulnerabilities
-Physical vulnerabilities
-Software vulnerabilities
-Communication & Network vulnerabilities
What should be included in a Cybersecurity Risk Assessment Report? - ✅✅-Scope of the risk
assessment
Assessment details
-Dates/Locations
, -Participants
-Risk Assessment Process
Risk profile
Summary of recommendations
Detailed findings
-High risk threats
-High risk vulnerabilities
-Prioritized recommendations
-Detailed risk assessment worksheets
What is the final task of the assessment phase? - ✅✅-Document System-Level Cybersecurity
Requirements
What should be included in the System-Level Cybersecurity Requirement? - ✅✅-Scope and purpose of
the system
Physical and environmental security requirements
General cybersecurity requirements
Zone and Conduit specific requirements
What ISA/IEC standard is the best source of IACS cybersecurity requirements? - ✅✅-ISA 62443-3-3
Cybersecurity Requirement Specification (CRS) - ✅✅-Document(s) that outlines the mandatory security
countermeasures for a System Under Consideration (SUC). It's based on the outcome of a detailed risk
assessment, along with general security requirements stemming from company or site-specific policies,
standards, and relevant regulations. The CRS includes a description of the SUC, zone and conduit
drawings, zone and conduit characteristics, operating environment assumptions, threat environment,
organizational security policies, tolerable risk, and regulatory requirements.
ZCR 6: Cybersecurity Requirements Specification - ✅✅-This ZCR calls for the creation of a Cybersecurity
Requirements Specification (CRS) that documents necessary security countermeasures for the System
Under Consideration (SUC). The CRS is informed by the detailed risk assessment and any pertinent
company or site-specific policies, standards, and regulations. It should include, at the very least, a SUC