Which is a common pitfall when initiating a CSMS program?
Select an option, then click Submit answer.
Reference / correct answer:
Failure to relate to the mission of the organization
Most accepted answer: B. Failure to relate to the mission of the organization
Community votes: B=4, D=2
Selected Answer: B Common pitfall is lack of management support thus no resources allocated upvoted 1 times
Answer is "B". Check page 157 - ISA62443-2-1: A common pitfall is to attempt to initiate a CSMS program without at least a high-level rationale that relates cyber security to the specific organization and its mission. upvoted 2 times
Selected Answer: B For CSMS common pitfall is lack of management support thus no resources allocated, answer is B. A = detailed risk assessment C = high-level risk assessment D = high-level risk assessment – Cybersecurity fatigue – Overwhelmed by number of issues – Avoid the “shiny object syndrome” upvoted 1 times
Selected Answer: B Correct answer is B. Answer D, "Immediate jump into detailed risk assessment" is a pitfall of "High-Level risk assessment" upvoted 2 times
Selected Answer: D We must select methodologies for identifying and prioritizing these risks and then execute those methodologies. We must identify them upfront and provide the structure for the rest of the risk assessment. We want to involve the stakeholders identified during the initiate step. The common pitfall here is to immediately jump into a detailed risk assessment. It's easy to do, especially with technical stakeholders. We have this shiny object syndrome that we tend to do, "Ooh, look at that. I'm going to go chase that for now. Ooh, look, I want to chase that for now." Avoid that shiny object syndrome, especially when you're doing the risk assessments. You get to see some cool things but you've got to stay focused and stay on track. IC32M page 190 upvoted 1 times