What caution is advised when using the vector approach to security levels?
A.
Vector approaches eliminate the need for risk models.
B.
Vector approaches are always more accurate than qualitative methods.
C.
Vector values should be ignored if they do not match industry standards.
D.
Vector values must align with the asset owner's risk matrix and risk appetite.
The Answer Is:
D
This question includes an explanation.
Explanation:
When using the security level (SL) vector approach in ISA/IEC 62443, each Foundational Requirement (FR) can have its own SL-T value. However, these values must reflect the organization’s specific risk assessment outcomes, not generic or industry default values.
“SL vectors should be derived based on the asset owner’s own risk matrix and risk tolerance, ensuring that the security levels support operational needs and business requirements.”