A corporate policy cites IEC 62443-2-1 as the basis for the plant cybersecurity program. What does that part specify?
- A.Security management program requirements for an asset owner
- B.Technical requirements for embedded controller hardware components
- C.Secure development lifecycle duties for a product supplier firm
- D.The risk assessment method used during system design
Why A is correct
Part 2-1 sets out the security program an asset owner must establish to run an IACS. Technical component requirements are in 4-2, the supplier lifecycle is in 4-1, and the system design risk method is in 3-2.
Know someone studying for OT Security Fundamentals? Send them this one.