In the CSMS risk-identification step, an OT team inventories systems and identifies threats and vulnerabilities. The most important reason to do this before selecting controls is that:
- A.Inventories are required by the building fire code
- B.Controls must be matched to actual risks rather than chosen blindly
- C.It allows the vendor to set the security budget
- D.It eliminates the need for management approval
Why B is correct
Risk identification produces the understanding of assets, threats, and vulnerabilities needed to select appropriate, proportionate controls. Without it, countermeasures would be guesswork and resources misallocated. IEC 62443-2-1 sequences identification ahead of treatment for this reason.
Know someone studying for ISA/IEC 62443? Send them this one.