A business rationale should be developed for managing the information security of the industrial control systems. The rationale should explain why information security management for industrial control systems is necessary, highlighting potential risks, threats, and the impact of inadequate protection. This includes operational disruptions, financial losses, and safety concerns. It should also define the roles of various organizations, the division of responsibilities, and, if appropriate, the list of assets to be managed.
The rationale may be part of the overall risk management strategy of the organization or a separate document, tailored to the management of industrial control systems.