What are the two elements of the risk analysis category of an IACS?
A.
Risk evaluation and risk identification
B.
Business rationale and risk reduction and avoidance
C.
Business rationale and risk identification and classification
D.
Business recovery and risk elimination or mitigation
The Answer Is:
C
This question includes an explanation.
Explanation:
According to ISA/IEC 62443-3-2, the risk analysis phase in the IACS security lifecycle includes both the business rationale and the risk identification and classification. This ensures that risk decisions are based not only on technical vulnerability but also on business impact and operational context.
“The risk analysis process includes identification and classification of risks based on a defined business rationale. This ensures that the protection requirements are aligned with the organization’s risk tolerance and operational priorities.”