Role
Asset Owner
The organisation that actually operates the IACS environment — for example a grid operator or energy producer — and is ultimately responsible for the risk.
Governance
Establishing policy, roles and responsibilities for OT security within the organisation.
Risk acceptance
Making informed decisions about which residual risks are acceptable, based on the risk assessment.
CSMS
Setting up and maintaining a Cybersecurity Management System in line with IEC 62443-2-1.
Asset inventory
Maintaining a current overview of all IACS components, including firmware and patch status.
Incident response
Having a practised process for detecting, following up on and recovering from security incidents.
Lifecycle management
Managing components from purchase to end of life, including replacement planning.
Supplier management
Setting security requirements for suppliers and integrators and laying them down contractually.