A manufacturer is establishing the foundational document that defines management commitment, scope, and high-level intent for protecting its industrial control systems. Under IEC 62443-2-1, which element of the Cybersecurity Management System provides this top-level statement?
- A.The incident response runbook
- B.The detailed firewall rule base
- C.The asset inventory database
- D.The corporate cybersecurity policy
Why D is correct
IEC 62443-2-1 places the corporate cybersecurity policy at the top of the CSMS hierarchy, where management commitment, scope, and intent are formally documented. Lower-level procedures and technical controls derive their authority from this policy. Without it, downstream activities lack governance and accountability.
Know someone studying for ISA/IEC 62443? Send them this one.