SCREENING FACILITIES FOR CYBER SECURITY RISK ANALYSIS
Paul Baybutt · 2003
Many chemical companies have performed security vulnerability analyses (SVAs) for their facilities since the middle of 2002 when the American Chemistry Council issued a new Security Code of Management Practice and required its member companies to follow it. The first step was to prioritize facilities for analysis using a simple screening scheme. These initial SVAs have focused on physical and personnel security and usually have not explicitly addressed cyber security. It is expected these SVAs will soon be extended to address cyber security. This paper provides a modification of the ACC screening scheme that can be applied to cyber security.