This discussion is locked.
You cannot post a reply to this discussion. If you have a question start a new discussion

cybersecurity assurance

Hello all,

I am the newly appointed lead cyber authority for a large energy company.  I am interested in your thoughts on what an assurance framework or assurance model  might look like in providing an independent view on cyber risk. 


Thanks,


Mike Ramesar
Parents
  • Your company will have lots of firmly installed kit. The IEC 62443 series is applicable and has a number of documents which address assessment and assurance. It seems Part 3-2 is relevant, but I haven't read it yet so don't really know how good I think it is. I have developed my own list of duties and mandates for process plant cybersec along with Martyn Thomas. It turned out to be way too long for the original target journal but we may be about to revise it for another. "Independent" it most certainly is. 

Reply
  • Your company will have lots of firmly installed kit. The IEC 62443 series is applicable and has a number of documents which address assessment and assurance. It seems Part 3-2 is relevant, but I haven't read it yet so don't really know how good I think it is. I have developed my own list of duties and mandates for process plant cybersec along with Martyn Thomas. It turned out to be way too long for the original target journal but we may be about to revise it for another. "Independent" it most certainly is. 

Children
No Data