IEC 62443-3-2 report
Preserve the result of the detailed risk process in a readable record.
Detailed risk work is expensive to do and easy to lose. The report keeps the reasoning, not just the conclusion, in a form that can be reread a year later and still make sense.
- The system under consideration, and the scenarios assessed against it
- Countermeasures, and the residual risk left after them
- Target Security Level proposals arising from the work
What is in it
The reasoning, not only the outcome.
Contents follow the current report model. Each item below is produced by the report as it exists today.
- Assessment identity
- Which assessment this is, and the methodology version it was carried out under.
- System under consideration
- The members that make up the scope of the assessment.
- Risk scenarios
- The scenarios assessed, against the scopes and conduits they concern.
- Countermeasures
- What is recorded as reducing the risk in each scenario.
- Residual risk
- What remains once the recorded countermeasures are taken into account.
- Per-subject summaries
- The picture for each scope or conduit in the assessment.
- Outstanding proposals
- How many Target Security Level proposals arising from the work have not yet been confirmed.
- Issuance metadata
- The version, digest, issuer and time recorded when the report was issued.
Where it comes from
The assessment it preserves.
The report is generated from the detailed IEC 62443-3-2 assessment held in the project. It is assembled server-side, so what is issued is what the product held rather than what a browser assembled from several requests.
Because targets are proposed here and confirmed elsewhere, the report records how many proposals are still outstanding rather than implying they have been accepted.

A record of the process, not a certificate.
The report records risk work carried out in line with the structure of IEC 62443-3-2. It is not certification, not an audit opinion, and not a statement that a zone, a conduit or a plant is compliant with the standard.
Related
Risk & Targets
How the detailed assessment proposes a target, and who confirms it.
Reports
The other report kinds, and issuance.
Keep the reasoning, not just the number.
See an issued IEC 62443-3-2 report generated from a real detailed assessment.