A CSMS classifies a risk as high likelihood and high consequence. The classification's main purpose in the next CSMS step is to:
A.Automatically close the risk without action
B.Drive prioritized selection of countermeasures for that risk ahead of lower-ranked ones
C.Hide the risk from management reporting
D.Defer the risk indefinitely regardless of severity
Why B is correct
Classifying a risk as high likelihood and high consequence flags it for prioritized countermeasure selection ahead of less severe risks, guiding resource allocation. Classification feeds directly into the addressing-risk phase. It would never justify hiding or indefinitely deferring a severe risk.
Know someone studying for ISA/IEC 62443? Send them this one.
CyberCertPrep gives you 20 free ISA/IEC 62443 questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
ISA/IEC 62443 and ISA/IEC are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by ISA/IEC or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
In the CSMS risk-identification step, an OT team inventories systems and identifies threats and vulnerabilities. The most important reason...