Skip to content

IEC 62443-3-2 report

Preserve the result of the detailed risk process in a readable record.

Detailed risk work is expensive to do and easy to lose. The report keeps the reasoning, not just the conclusion, in a form that can be reread a year later and still make sense.

  • The system under consideration, and the scenarios assessed against it
  • Countermeasures, and the residual risk left after them
  • Target Security Level proposals arising from the work

What is in it

The reasoning, not only the outcome.

Contents follow the current report model. Each item below is produced by the report as it exists today.

Assessment identity
Which assessment this is, and the methodology version it was carried out under.
System under consideration
The members that make up the scope of the assessment.
Risk scenarios
The scenarios assessed, against the scopes and conduits they concern.
Countermeasures
What is recorded as reducing the risk in each scenario.
Residual risk
What remains once the recorded countermeasures are taken into account.
Per-subject summaries
The picture for each scope or conduit in the assessment.
Outstanding proposals
How many Target Security Level proposals arising from the work have not yet been confirmed.
Issuance metadata
The version, digest, issuer and time recorded when the report was issued.

Where it comes from

The assessment it preserves.

The report is generated from the detailed IEC 62443-3-2 assessment held in the project. It is assembled server-side, so what is issued is what the product held rather than what a browser assembled from several requests.

Because targets are proposed here and confirmed elsewhere, the report records how many proposals are still outstanding rather than implying they have been accepted.

The OTReady IEC 62443-3-2 risk assessment workspace, showing the system under consideration and the recorded risk scenarios.
The assessment the report is generated from.

A record of the process, not a certificate.

The report records risk work carried out in line with the structure of IEC 62443-3-2. It is not certification, not an audit opinion, and not a statement that a zone, a conduit or a plant is compliant with the standard.

Related

  • Risk & Targets

    How the detailed assessment proposes a target, and who confirms it.

  • Reports

    The other report kinds, and issuance.

Keep the reasoning, not just the number.

See an issued IEC 62443-3-2 report generated from a real detailed assessment.