IEC 62443-3-2 carries the title "Security risk assessment for system design." Which deliverable sits at the center of the workflow it defines?
A.A documented set of zones, conduits, and target security levels for the IACS under consideration
B.A continuous monitoring playbook for the security operations center
C.A product certification report for embedded controllers
D.An incident response runbook tailored to OT environments
Why A is correct
IEC 62443-3-2 drives a risk-based partitioning of the system under consideration into zones and conduits and the assignment of target security levels (SL-T). It is a design-time standard, not an operational monitoring or product-certification document.
Know someone studying for ISA/IEC 62443? Send them this one.
CyberCertPrep gives you 20 free ISA/IEC 62443 questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
ISA/IEC 62443 and ISA/IEC are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by ISA/IEC or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
A CSMS classifies a risk as high likelihood and high consequence. The classification's main purpose in the next CSMS step is to: