Risk Assessment Methods
Jean‐Marie Flaus · 2019
Managing cybersecurity in an industrial control system involves an important proactive phase, which consists of implementing measures to reduce the likelihood of an attacker generating damage to the system. This approach is described by the risk management process of ISO 27005. The objective of risk analysis methods is only to provide an approach to identify and assess the risks of an information system that is as systematic as possible. This chapter presents in more detail the main steps of a risk analysis method. Attack trees are a graphical representation of combinations and sequences of events that describe the different ways in which a system can be attacked. A cyber Preliminary Hazard Analysis (PHA) can be seen as an extension of a PHA by taking into account cybersecurity issues in the case of a feared event and for barrier failures.