An OT security program defines a step-by-step document stating exactly how new user accounts on control systems are requested, approved, provisioned, and periodically reviewed. Within the CSMS this is best categorized as a:
A.Marketing collateral
B.Network diagram
C.Business impact analysis
D.Security procedure for account management
Why D is correct
A step-by-step document governing account request, approval, provisioning, and review is a security procedure that operationalizes account-management policy within the CSMS. Such documented procedures translate high-level policy into repeatable actions. They also provide audit evidence of consistent control.
Know someone studying for ISA/IEC 62443? Send them this one.
CyberCertPrep gives you 20 free ISA/IEC 62443 questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
ISA/IEC 62443 and ISA/IEC are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by ISA/IEC or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
A CSMS classifies a risk as high likelihood and high consequence. The classification's main purpose in the next CSMS step is to: