What must be established as part of the risk assessment process?
A.
Total elimination of risks
B.
Increased budget allocation
C.
Target Security Level (SL-Ts)
D.
New technology implementation
The Answer Is:
C
This question includes an explanation.
Explanation:
The ISA/IEC 62443-3-2 standard specifies that a key output of the risk assessment process is the establishment of Target Security Levels (SL-Ts) for each security zone or conduit. These target levels define the minimum cybersecurity requirements necessary to mitigate identified risks to an acceptable level. Total risk elimination is generally not possible; instead, setting SL-Ts allows for structured, risk-based implementation of security controls.