160
CYBerseCurItY For InDustrIAL ControL sYsteMs
the probability of detecting threats or compromises of ICS assets or
understanding the degree of threats ranged against those assets.
Conclusion
In the course of this chapter we have taken the reader through 12 dif-
ferent forms of risk assessment aimed at or adopted to ICS security. Of
these systems, we considered the rst eight to be well known and largely
derivatives of well-understood qualitative risk assessment processes. In
other words, risk assessment processes tend to rely upon measurements
and metrics that might be dierent from one assessor to another, and
therefore are more prone to inconsistent results. ese qualitative sys-
tems for ICS risk assessment have the benet of tradition and ...