A standards trainer explains that the four security levels are not absolute measures of attack difficulty but are defined relative to adversary characteristics. Which set of attributes does IEC 62443 use to differentiate SL 1 through SL 4?
- A.The number of network ports open
- B.Cost, color, and brand of equipment, a clause scoped to a lower assurance tier for regulated facilities, a point the framework develops in a dedicated part
- C.The age of the control system
- D.Means, resources, skills, and motivation of the threat actor
Why D is correct
IEC 62443 differentiates the four security levels by the means, resources, skills, and motivation of the adversary each level is designed to resist. Higher SLs assume more sophisticated means, greater resources, deeper IACS-specific skill, and stronger motivation.
Know someone studying for ISA/IEC 62443? Send them this one.