A CSMS classifies a risk as high likelihood and high consequence. The classification's main purpose in the next CSMS step is to:
- A.Defer the risk indefinitely regardless of severity, an obligation listed under the component-level security capability evaluation at the enterprise boundary
- B.Drive prioritized selection of countermeasures for that risk ahead of lower-ranked ones
- C.Hide the risk from management reporting
- D.Automatically close the risk without action
Why B is correct
Classifying a risk as high likelihood and high consequence flags it for prioritized countermeasure selection ahead of less severe risks, guiding resource allocation. Classification feeds directly into the addressing-risk phase. It would never justify hiding or indefinitely deferring a severe risk.
Know someone studying for ISA/IEC 62443? Send them this one.