Summary
The aim of this course is to learn the fundamental principles for cyber security in the context of the risk assessment method to be applied in the process industries according to IEC 62443 and to understand the role and the process of Security Risk Assessment (SRA) in gaining an understanding of the security risks on the facility and their potential consequences.
The training will further establish the concept of Security Level Targets (SLT) and the Cyber Security Requirements Specification (CSRS). This will also include the relationship between the SLT and the CSRS to the design and implementation of security countermeasures that are capable and able to achieve the security requirements needed of the determined security level for Industrial Automation Controls Systems (IACS).
Course attendance is open to all interested parties and achieving the threshold mark for the examination (in combination with already having successfully passed the examination for the TÜV Rheinland fundamentals of cyber security training course) will result in the candidate receiving a ‘TÜV Rheinland Cyber Security Specialist RA’ training certificate.
Learning objectives
Upon completion of this course, the participants should be able to understand:
- The requirements for IACS security in the context of relevant standards and cyber security frameworks
- The most common approaches that are available to achieve security and what activities must be carried out
- How SRA is carried out and the relationship to the IACS zones and conduits
Topics covered:
- Background on cyber security standards and industry guidance i.e. IEC 62443
- Introduction to IACS security and the relevant standards and regulations
- Approach to ensuring cyber security asset inventory
- Introduction to Security Risk Assessment (SRA)
- High-level SRA requirements
- Allocation of IACS to zones and conduits
- Detailed-level SRA requirements
- Determining the level of security risk and the security level
- Risk management
- Monitoring and review
When
Tuesday 10 November 2026, 09:00-16:30
Wednesday 11 November 2026, 09:00-16:30
Thursday 12 November 2026, 09:00-16:30
Friday 13 November 2026, 09:00-16:30
Course type
The first 3 days led by an instructor discussing the implementation of cyber security in the context of relevant industry standards and technical implementation requirements. The 4th day will feature an online examination and for those that are successful, a ‘TÜV Rheinland Cyber Security Specialist RA’ training certificate will be issued.


