Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Security risk assessment

Also known as: Cybersecurity risk assessment, Security risk analysis

German: Risikobeurteilung (Security Risk Assessment)

In OT cybersecurity, a security risk assessment is the systematic identification of threats and vulnerabilities of an industrial automation and control system, the estimation of the likelihood and consequences of their exploitation, and the derivation of zones, conduits and target security levels. IEC 62443-3-2 describes the process.

  • OT security
  • Standards

In one sentence

A security risk assessment finds threats and vulnerabilities of a control system, estimates risk and derives zones, conduits and target security levels.

Example

In the security risk assessment for a new mixing plant, the team identifies remote maintenance as a high-risk entry point and assigns the controller zone a target security level of 2.

Explained in context

Context cards connect this term with others to answer one question. Also in British English and German.

How it applies

  • Engineering: IEC 62443-3-2 starts with the system under consideration, performs an initial high-level assessment, partitions the system into zones and conduits, then performs a detailed assessment per zone to set the target Security level (SL) and required countermeasures.
  • Safety: Consequences in OT include physical harm and environmental damage. The assessment should use results of the safety Risk assessment and HAZOP, and safety experts should take part.
  • Maintenance: The assessment is repeated when the system, the threat situation or the use changes.
  • Documentation: The results form the basis of the cybersecurity requirements specification. Keep the assessment, assumptions and residual risks under document control; product documentation should state the security assumptions that the operator's assessment must cover.

Security risk assessment vs. machinery risk assessment

The machinery Risk assessment under ISO 12100 addresses hazards to people from the machine, including foreseeable misuse. The security risk assessment addresses intentional and unintentional compromise of the control system. They are separate analyses that must be linked where attacks can create hazards.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: IEC 62443-3-2:2020, Security for industrial automation and control systems — Part 3-2: Security risk assessment for system design

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!