OT Risk & Architecture Methodology

This methodology guides the assessment from business context through to OT architecture, risk identification, controls, residual risk, treatment decisions, and approval. It is designed to align business objectives, operational processes, assets, zones, conduits, risks, and controls in a structured IEC 62443 and GRC-aligned workflow.

🏒

Step 1 of 12

Understand the Business

Summary

Capture business objectives, critical services, regulatory drivers, operational priorities, and risk appetite. This ensures the assessment is aligned to what the business is trying to protect and achieve.

Information Required from Stakeholders

  • Business objectives
  • Critical services
  • Operational priorities
  • Risk appetite
  • Regulatory or compliance obligations