scada-risk-management-1

Q1. Patching ICS/SCADA systems are riskier than a traditional IT systems, and the book refers to three fundamentals of patching ICS/SCADA. Find an article about ICS/SCADA patch and /or change management and how it relates to at least one of the fundamentals. How might you use the information you find to an organization such as in your final project.

Q2. Identify, Measure, and Manage Risks

1. Identify risks:

Risk is a function of M, AV, T, and V:

R = f (M, AV, T, V)

R – risk, M – mission importance, AV – asset values, T – threats, V – vulnerabilities

2. “What”: what is the problem/challenge in managing risks and auditing the ICS? Explain how you might measure

“Why”: why do you need and want to solve the problem?

“How”: how do you economically solve it?

Identify Security Controls

3. Select security controls based on results from “Industrial Control System Processes Employed” and “Profile ICS Devices”:

Reference either ICS CERT CSET or NIST 800-53, Security and Privacy Controls for Federal Information Systems and Organizations,

http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf

 
Do you need a similar assignment done for you from scratch? We have qualified writers to help you. We assure you an A+ quality paper that is free from plagiarism. Order now for an Amazing Discount!
Use Discount Code "Newclient" for a 15% Discount!

NB: We do not resell papers. Upon ordering, we do an original paper exclusively for you.