Cyber Security Risk Assessment

The aim of this course is to learn the fundamental principles for cyber security in the context of the risk assessment method to be applied in the process industries according to IEC 62443 and to understand the role and the process of Security Risk Assessment (SRA) in gaining an understanding of the security risks on the facility and their potential consequences.

Upcoming Courses

Outline

  • Background on cyber security standards and industry guidance i.e. IEC 62443
  • Introduction to IACS security and the relevant standards and regulations
  • Approach to ensuring cyber security asset inventory
  • Introduction to Security Risk Assessment (SRA)
  • High-level SRA requirements
  • Allocation of IACS to zones and conduits
  • Detailed-level SRA requirements
  • Determining the level of security risk and the security level
  • Risk management
  • Monitoring and review

Who is this for?

This training is targeted to engineers, managers, consultants and specialists who require a general introduction and awareness to delivering a high-level IACS cyber security risk assessment from within the following  process industry user groups:

  • Asset owner / end user
  • Engineering contractors / EPCs
  • Power and automation system integrator’s 
  • Service providers
  • Product manufacturers

The course is particularly useful for those managers and engineers who may be directly or indirectly, involved in executing projects and/or operating and maintaining such IACS with a particular focus on the requirements and arrangements for conducting appropriate cyber security risk assessments.

In accordance with the TÜV Rheinland Functional Safety and Cybersecurity Program:

  • A minimum of 3 to 5 years’ experience in a related field (e.g. Control & Instrumentation, process engineering, IT/OT, functional safety or cybersecurity).
  • University degree or equivalent engineering experience and responsibilities as certified by employer or engineering institution.

At the end of the course you should be able to:

  • The requirements for IACS security in the context of relevant standards and cyber security frameworks
  • The most common approaches that are available to achieve security and what activities must be carried out
  • How SRA is carried out and the relationship to the IACS zones and conduits

This course can be customised and delivered at a location that suits you.

Contact our training team to find out how we can support your training needs.

This course is included in our public course schedule.

Register Your Interest