Managing information security is not a one-time task, but rather an ongoing one that is usually mapped within processes. These processes are designed to ensure that information security is achieved or maintained at an acceptable level over time. The graphic below illustrates this concept and compares it with the approach whereby security is conceived merely as a project.

Fig. Security level over time (source: IEC 62443-1-1)
The necessary processes are combined in an ISMS (information security management system) and can thus be managed more easily.
In the first step, an inventory of the company is taken and all relevant systems, processes, and employees are identified in a risk assessment and evaluated with regard to potential vulnerabilities and their impact. This analysis provides the basis for the subsequent creation of technical and organizational measures, such as policies to be documented and the roll-out of solutions to minimize any vulnerabilities or risks found. The effectiveness and efficiency of these measures are continuously reviewed and improved.
This process is repeated cyclically and thus continuously improves the organization's security level.

Fig. Continuous process with an ISMS
|
Step |
Description |
|---|---|
|
Risk assessment |
This step is about identifying and assessing risks in the plant. What are the threats and vulnerabilities?
|
|
Policies, organizational measures |
For some risks, there is either no technical solution or it is not financially commensurate with the risk. Such risks are best mitigated through policies and targeted employee-awareness training. These measures also include, for example, the designation of responsible persons who, when production is restarted after a security incident, execute defined and trained evaluation and documentation procedures. |
|
Technical measures |
Here, risks are minimized by means of customized technical solutions that allow control of organizational measures and enable the company to implement state-of-the-art security standards. |
|
Audits and improvement |
Independent audits should be conducted. The most suitable auditors are security experts from outside the company who are able to critically evaluate its technical infrastructure. They can impartially assess whether the implemented measures are effective and make recommendations for improvement. |