Iec 62443 Exam Review Questions And Answers, Graded A+/ Verified.
IEC 62443 EXAM REVIEW QUESTIONS AND ANSWERS, GRADED A+/ VERIFIED. IACS - -Industrial Automation and Control Systems. Example: A nuclear power plant control room Threat - -The adversary's goals or what they might try to do a system. Example: steal money or steal passwords. Threat Agent - -The attacker or adversary. Example: some bad guy in North Korea. Asset - -An abstract or concrete resource that must be protected from misuse by an adversary. Example: Credit card number, web server Attack pattern - -General strategies an adversary might use to break into a system. Not a specific vulnerability. Example: SQL injection, or buffer overflow Exploit - -Instance of an attack pattern. Taking advantage of a specific flaw to do something bad. Example: buffer overflow in a JSON parsing library Attack - -Act of carrying out an exploit ICS - -Industrial control systems CRT testing - -Communication Robustness testing Cyber Priorities of an IT department - -(1) Confidentiality (2) integrity (3) availability Cyber Priorities for ICS - -(1) availability (2) integrity (3) confidentiality ISO 27001 - -General IT security certification Software security assurance - -Security level of software depends on the consequences of the software being compromised. Example: Wikipedia needs less security than a nuclear power plant 4 main themes of IEC 62443 - -(1) General (2) Policies and Procedures (3) System (4) Component 8 fundamental practices in IEC 62443 - -(1) Security management (2) Specification of security requirements (3) Secure by design (4) Secure implementation (5) Security verification and validation testing (6) Management of security related issue
Document information
- Uploaded on
- April 11, 2024
- Number of pages
- 8
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers