| |
Criticality |
The potential impact
of ICS incidents leading to a loss of availability of the
process control capability, integrity of control data or
confidentiality of information.
Availability disruption can be measured on a scale from
milliseconds to days or longer, depending on the nature of
the controlled process. |
|
| |
Status of controls |
The status of
controls measured against a library of industry best
practice controls drawn from many sources such as CPNI
Good Practice Guides to process control and SCADA security
and NIST 800-82. Organizations can use the
Citicus-supplied control framework off-the-shelf or
augment/replace it with their own set of controls. |
|
| |
Special circumstances |
Particular
characteristics of the ICS that can drive risk up, such as
high degree of change, complexity, interconnection to other
systems, accessibility by external parties. |
|
| |
Level of threat |
An indicator of
incident probability through metrics of past incidents such
as malfunctions, human error, malicious action, disruption
from environmental events. |
|
| |
Business impact |
The actual business
harm caused by previous ICS incidents, if any.
Harm is measured in an objective and consistent way and
covers all types of business impact such as financial loss,
reputational damage, environmental and safety impacts. |
|