A project team must decide the target security level of a zone. Which activity sets SL-T in the IEC 62443 approach?
- A.Vendor datasheet capability claims about the installed devices
- B.Penetration test results gathered after the whole system is commissioned
- C.The lowest certificate rating among devices inside the zone
- D.Zone risk assessment weighing threat likelihood against consequence
Why D is correct
SL-T results from the zone and conduit risk assessment in 3-2, which compares threats and consequences with the tolerable risk. Datasheets and later tests inform other values such as SL-C and SL-A.
Know someone studying for OT Security Fundamentals? Send them this one.