Abstract :
Summary form only given. In this era of increased security visibility and risk, companies are searching for ways to secure their system. Knowing what path to take requires a detailed knowledge of the current state of security risk. The security assessment provides a way to determine risk and is a platform on which to build a solution. However, done wrongly, the assessment can threaten the availability of your control system and yield largely useless results. Done rightly, the assessment provides not only a risk assessment, but a set of policies essential for implementing a security solution, a properly crafted solution architecture, and even an increase in reliability and availability. This presentation examines the issues surrounding control system assessments, the elements of success and the questions that must be answered in choosing a vendor for a security assessment.