106
CYBerseCurItY For InDustrIAL ControL sYsteMs
persist. A related conclusion is that assessing risk to ICS based entirely
or even partially upon known vulnerabilities is questionable.
For these reasons, our discussion on technical ICS vulnerabilities
will seek to establish useful frameworks for assessing and describ-
ing vulnerabilities, rather than specic vulnerabilities themselves.
e benet of this approach is that vulnerabilities that are unique to
ICS become easier to recognize once a descriptive paradigm has been
established. By understanding in a generic manner how to describe
and where to expect vulnerabilities in any ICS, it becomes easier to
describe them in our own systems. From here, the ability to eectively
describe and recogn ...