135
rIsk AssessMent teChnIques
In other words, ICS risk assessors do not know what they do not
know about ICS and should therefore calculate risk backwards from
an ideal state by assessing how far a target of evaluation is from this
state. At the very least, this will provide a minimum reading of risk,
since it does not start with the premise that the most likely threats
can be enumerated. Instead, the ideal-based system, they say, creates
the ideal ICS security architecture, including the dened metrics, and
then assesses against how much of the ideal is reected in the current
system and perhaps in future planned improvements.
As a fresh approach, the ideal-based system certainly possesses
merit, but it also immediately leads to complex ...