The formula for risk in ISA/IEC 62443 is typically expressed as:
Risk = Threat × Vulnerability × Consequence
This means that risk is a product of the likelihood that a threat will exploit a vulnerability and the impact (consequence) if that event occurs. This formula is consistently used in both the general information security domain and explicitly referenced in the ISA/IEC 62443-3-2 standard in the context of IACS risk assessments.
[Reference: ISA/IEC 62443-3-2:2020, Section 5.2 (“Risk is typically calculated as Threat × Vulnerability × Consequence”); ISA/IEC 62443-2-1:2009, Section 5.2.4., , ]
Submit