| Threat and Risk Assessment | | | | | | | | Risk Treatment Plan |
| Asset ID | Common potential points of failure and known vulnerabilities | Threat Type | Threat sources | Consequence | Current Risk Likelihood | Risk Rating | Treatment Option & reference | Control Objectives | Selection of controls to achieve objectives | Consequence | Likelihood of Occurrence | Residual Risk |
| People | Personnel with low technical skills | Availability | T1,T2 | Moderate | Almost certain | High | Reduce A3 | Ensuring all the required resources are available to manage and operate SCADA systems | Skill improvement sessions for the staff members | Moderate | Unlikely | Medium |
| | Careless about their personal informations such as user ids, password etc. People write it on stick notes paste on their desks | | T1,T2 | | | | | | Implementing electronic token generation on staff cell phones to provide access to their systems |
| | short term contract employees | | T1,T2 | | | | | | Access to business secrets must be restricted to contract employees |
| | People who resigned from the company can reveal the confidential information | Confidentiality | T1,T2 | Moderate | Likely | High | Reduce A1 | Sensitive SCADA information must be kept confidential by the people | Restrict ex-employee access to company database. | Moderate | Unlikely | Medium |
| | Employees getting help from people outside organization to get their job done can lead to risk of revealing confidential information | | T1,T2 | | | | | | Role based access system to the registered employees devices |
| | Unaware of consequences if something goes wrong while handling critical things | | T1,T2 | | | | | | Well documented and circulated response procedures among employees |
| | All the employee activities such as system access, contacts etc should be monitored constantly | Integrity | T1,T2 | Moderate | Likely | High | Reduce A2 | Ensuring all the SCADA resources are adequately trained, motivated and are loyal | Monitoring systems must be installed and systems logging must be maintained | Moderate | Unlikely | Medium |
| | Unethical way of using organizations software or try to break it using virus or malicious code | | T1,T2 | | | | | | Restrict use of social media, flashdrive and implement admin restrcition for installing new softwares or changes |
| Management | Various policies related to security issues have to be taken into consideration | Integrity | T1, T2, T3, T4, T5 | Catastrophic | Likely | Extreme | Reduce B2 | Providing correct and controlled access to SCADA information | Develop security policies based on NIST framework | Minor | Unlikely | Low |
| | No efficiency in work done by the employees | | T1, T2, T3, T4, T5 | | | | | | Proper performance measurement indicator systems must be implemented |
| | No proper agreements at various levels such as service level agreements | | T1, T2, T3, T4, T5 | | | | | | Third party consultation for vetting service level agreements (SLAs) |
| | Poor allocation security roles and responsibilities, No proper authorization based on designation | Confidentiality | T1, T2, T3, T4, T5 | Catastrophic | Likely | Extreme | Reduce B1 | Providing incident response and readiness processes | Developing incidence response plan along with assigned staff member | Minor | Unlikely | Low |
| | Lack of appropiate response to the security issues | | T1, T2, T3, T4, T5 | | | | | | Developing Incidence handling guide as per NIST standards |
| | On frequent basis proper reviwening all operation procedures, implementations and planning | Availability | T1, T2, T3, T4, T5 | Catastrophic | Likely | Extreme | Reduce B3 | Ensuring dedicated and effective Management support for SCADA systems | Updating SCADA management policies and procedures | Moderate | Unlikely | Medium |
| | weak and lame personnel in security committee | | T1, T2, T3, T4, T5 | | | | | Requiremnt of well defined management controls | Implementing Key Performance Indicators & measurements for staff operations |
| Building/Site management | Lack of proper maintainence handeling | Integrity | T1, T2 | Minor | Possible | Medium | Reduce C2 | To prevent loss to site and infrastructure | Develop incident response and emergency procedures | Minor | Unlikely | Low |
| | Natural disasters | | T1, T2 | | | | | | Develop & circulate disaster reovery and business continuity plans (BCP) |
| | losses and harm caused to personnel and service due to Environmental hazards | Availability | T1, T2 | Moderate | Unlikely | Medium | Reduce C3 | To ensure safety of assets and normal operations after interruption to the SCADA operations | Develop Health Safety & Environment (HSE) Policy and the establisment must be able to with stand any inclement weather | Minor | Unlikely | Low |
| | No proper planning and designing | | T1, T2 | | | | | | Develop disater management plan and use of uninterruptible power supply (UPS) |
| | No proper security for property and infrastructure | | T1, T2 | | | | | | Defining security measures for establishment |
| | Environment in office not secured or less secured | Confidentiality | T1, T2 | Minor | Possible | Medium | Reduce C1 | To prevent interruption to business processes and to avoid compromise of assets | Required protection systems against fire, wind, water and snow must be implemented | Minor | Unlikely | Low |
| Information Management | Constantly monitoriing and auditning the softwares | Integrity | T1, T2 | Moderate | Almost Certain | High | Reduce D2 | To ensure proper operation of systems using information monitoring | Periodically updating all the software applications | Moderate | Unlikely | Medium |
| | Strong Password policy should be entact and enforced | | T1, T2 | | | | | | Implementing electronic token generation for access to individual systems |
| | Ex-employees access id and password should be regularly monitered to avoid un-authorized and illegally actvities | | T1, T2 | | | | | | Disabling ex-employees access rights |
| | Access control should be limted to concerned people to protect un authorized access | | T1, T2 | | | | | | Access to business secrets will be limited only to the concerned persons and information must be encrypted |
| | Any software update should be done from licensed copies only | Availability | T1, T2 | Moderate | Almost Certain | High | Reduce D3 | Information processes maintains systems availability | Patching of the software with regual updated from the licensed providers | Moderate | Unlikely | Medium |
| | Installing inappropriate hardware/software or without proper knowledge | | T1, T2 | | | | | | Enabling systems administration restriction on all systems in the network |
| | Recovery plan or devices should be continously monitered | | T1, T2 | | | | | | Regularly updating the recovery plan with lessons learned documents |
| | unorganized and inadequacy in data management may leads to data breach | Confidentiality | T1, T2 | Moderate | Almost Certain | High | Reduce D1 | Ensuring access control to SCADA systems | Efficient operating manuals will maintain data properly | Moderate | Unlikely | Medium |
| | Policies and procedures should be up to data and documented | | T1, T2 | | | | | | Periodical reviews and updating all the operating procedures and manuals |
| | | | T1, T2 |
| Communication and Network | Mis interpretation of information may results in breach of the data | Confidentiality | T1, T2 | Minor | Likely | Medium | Reduce E1 | To protect the SCADA information during transmission of data | Prescribed encryption methods must be implemented to secure data | Minor | Unlikely | Low |
| | loop holes in policies, rules of network equipment. | | T1, T2 | | | | | | Use of well documented SCADA operating procedures and device manuals |
| | weak segment network leads to network valunerability | | T1, T2 | | | | | | Perform vulnerability assessments on all access points into the SCADA network |
| | Unprotected wireless channels grant unapproved access, network breach. | | T1, T2 | | | | | | Detecting unauthorized user in the network using intrusion detection systems (IDS) |
| | Unethical hacking, cyber attacks, interruptions in data transmissions | Integrity | T1, T2 | Moderate | Almost Certain | High | Reduce E2 | To secure network configurations | Applying encryption protocols like ISM Cryptography, ISO and NIST standards | Moderate | Unlikely | Medium |
| | No proper time to time network activity analysis | | T1, T2 | | | | | | Implementing of systems logging for detecting any unauthorized access or activity |
| | Eradicating irrelevant information | Availability | T1, T2 | Moderate | Almost Certain | High | Reduce E3 | Maintaining network connectivity | Applying dataming techniques | Moderate | Unlikely | Medium |
| | Obstruction from different devices | | T1, T2 | | | | | | Conducting systems integration testing to identify any compactibility issues |
| SCADA Application Software | Lack of new technology | Integrity | T1, T2 | Major | Likely | High | Reduce F2 | To maintain all the systems and software updates | Regular updating of old SCADA system with new devices | Moderate | Unlikely | Medium |
| | Use of licensed software | | T1, T2 | | | | | | Buying the licensed software from the certified software vendor |
| | Challenges in maintaining the modern software | | T1, T2 | | | | | | Proper contracts must be made with the software vendors for updating the patches |
| | Network crash | Availability | T1, T2 | Major | Likely | High | Reduce F3 | To ensure effective change management | Acceptance testing must be carried out before installing new devices to prevent crash | Moderate | Unlikely | Medium |
| | User fails to cope up with the required changes | | T1, T2 | | | | | | Required training must be provided to the staff for any change management |
| | Lack of knowledge of the new introduced software | | T1, T2 | | | | | | Thorough working process and trainig needs to be given to the staff |
| | Difficulty in software maintenance | | T1, T2 | | | | | | Developing prescribed maintenace manuals with reference to industry standards |
| | Problem faced through stern security | Confidentiality | T1, T2 | Moderate | Likely | High | Reduce F1 | To ensure security mechanisms in place to withstand unauthorised access attempts | Conducting acceptance testing to verify compactibility with security systems | Moderate | Unlikely | Medium |
| SCADA Hardware including operating System | Application Inconsistency | Integrity | T1, T2 | Moderate | Likely | High | Reduce G2 | To ensure proper configuration | Configuration management and control procedures to ensure proper working | Moderate | Unlikely | Medium |
| | Management failure | Confidentiality | T1, T2, T3, T4 | Moderate | Almost Certain | High | Reduce G1 | To ensure resilience against foreign access control | Implementing change management process and control strategies | Moderate | Unlikely | Medium |
| | possibility of system accessible by many | | T1, T2 | | | | | | Enabling role based access controls |
| | Improper access codes | | T1, T2 | | | | | | Implementing electronic token systems for access |
| | Failure of equipment | Availability | T1, T2 | Moderate | Almost Certain | High | Reduce G3 | To ensure normal operation after any disruption | Stocking up of spare devices for any equipment failure | Minor | Possible | Medium |
| | Lack of extra quipment | | T1, T2 | | | | | | Making necessary arrangements for any extra equipments |
| | Power failures | | T1, T2 | | | | | | Using UPS and backup diesel generators |
| | No proper monitoring and planning | | T1, T2 | | | | | | Implementing inventory management for all the hardware and software components |
| SCADA Field Devices | Failure in security hardening | Confidentiality | T1, T2 | Moderate | Likely | High | Reduce H1 | To prevent unauthorised access to network | Use of encrypted data communication systems | Minor | Unlikely | Medium |
| | Having same default security configuration for every system | | T1, T2 | | | | | | Applying network segmentation to isolate one system from the other |
| | Using older username and password | | T1, T2 | | | | | | Deactivation of default old accounts and changing it once every month |
| | physicial damage | Availability | T1, T2 | Moderate | Almost Certain | High | Reduce H3 | To ensurecontrolling of devices and services | Using solid framework for rack and stack of devices | Minor | Unlikely | Medium |
| | access to the service | | T1, T2 | | | | | | Generation of electronic token for user access |
| | Hardware and Software application | Integrity | T1, T2 | Minor | Likely | Medium | Reduce H2 | To ensure stability of devices | Regular updating and servicing of devices and applications | Minor | Unlikely | Low |
| | use of other devices for operating | | T1, T2 | | | | | | Conducting acceptance testing prior to use of any device |
| Supporting Utilities | power deficiency | Integrity | T1, T2 | Moderate | Likely | High | Reduce I2 | Ensuring normal operation in the event of power interruptions | Power must be supplied by use of UPS, solar, wind and backup diesel generators | Minor | Unlikely | Medium |
| | backup power defieciency | Availability | T1, T2 | Major | Likely | High | Reduce I3 | Preventing disruption to SCADA operations during power failure. | Having portable power supply arrangement from market vendors | Moderate | Unlikely | Medium |
| | Capacity planning | | T1, T2 | | | | | | Establishing a 5 day power back systems using combination of UPS, solar and diesel generators |
| | Damage to utilities which are used in support | | T1, T2 | | | | | | Appropriate power conditioning devices must be used to protect devcies |
| | Breach of confidentiality | Confidentiality | T1, T2 | Minor | Possible | Medium | Reduce I1 | Protecting SCADA systems from compromise during power failure | Employing intrusion detection and protection systems (IDPS) | Minor | Rare | Low |