ISA 62443 Cybersecurity Fundamentals Exam IC32 || With Questions & Answers (Graded A+)
ISA 62443 Cybersecurity Fundamentals Exam IC32 || With Questions & Answers (Graded A+) ISA 62443 Cybersecurity Fundamentals Exam IC32 || With Questions & Answers (Graded A+) What does ISA-62443 1-1 Cover? - ANSWER - Basic Concepts and models related to cybersecurity. The difference between IT and IACS, Defense-in-Depth and Security zones and conduits. The difference between IT and IACS - ANSWER - IACS Cybersecurity has to address issues of health, safety and environment (HSE). IT - Confidentiality - Integrity - Availability. IACS - Availability - Integrity - Confidentiality. With IACS there are lives on the line - downtime/rebooting not acceptable. ISA-62443-1-1 - ANSWER - Concepts and Models ISA-62443-2-1 - ANSWER - Security program requirements for IACS asset owners ISA-62443-3-3 - ANSWER - System security requirements and security levels 3 most important 62443 primary groups - ANSWER - 1-1 2-1 3-3 IEC - ANSWER - International Electrotechnical Commission ISO - ANSWER - International Organization for Standardization ISA99 Membership types - ANSWER - 1. Information - Draft but no voting 2. Voting - must vote and only 1 per company 3. Alternate - Voting backup Explain the IACS Cybersecurity Lifecycle and the activities in each phase. - ANSWER - 1. Asses (Assign a SL-T) (IC33) 2. Develop and implement (Countermeasures implemented to meet SL-T) (IC34) 3. Maintain (Ensure countermeasures maintain or exceed SL-A) (IC37) Discuss the IACS Automation Solution Security Lifecycle from ISAGCA. - ANSWER - This lifecycle assigns responsibilities and accountability to each member involved in a IACS. Including Owner, Supplier, Integrator and Maintainer. Specification, Design, Implementation, Verification and validation, Operation, Maintenance and Decommissioning COTS - ANSWER - Commercial off the shelf These 3 things should be assessed and combined make up a risk assessment - ANSWER - Physical security, HSE, Cybersecurity What is step one of a detailed risk assesment? - ANSWER - Inventory IACS systems, networks and devices Why should we do a high level risk assessment before a detailed risk assessment?
Written for
- Institution
- Cyber Security Specialist
- Course
- Cyber Security Specialist
Document information
- Uploaded on
- July 14, 2024
- Number of pages
- 10
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers
Subjects
- what is isa99
-
isa 62443 cybersecurity fundamentals exam ic32
-
how many top level activities in a csms
-
compare nist csf to isaiec 62443
-
what are the 4 work product organization groups