Risk Management Framework for Facility-Related Control Systems AHA (Activity Hazard Analysis / Job Hazard Analysis)

Updated 2026-06-23

A Risk Management Framework for Facility-Related Control Systems AHA (Activity Hazard Analysis / Job Hazard Analysis) plans the structured process for managing cybersecurity risk across facility control systems — the governing framework that decides, implements, and maintains the security measures the DDC and SCADA docs describe. Where those docs are the measures, this one is the process that governs them.

Securing control systems isn't a checklist applied uniformly; it's a risk-based process that decides what protection each system needs and manages it over time. The Risk Management Framework (RMF) provides that process — a structured lifecycle of categorizing a system by its risk, selecting and implementing appropriate security controls, assessing them, formally authorizing the system to operate, and continuously monitoring it. Applied to facility-related control systems, this framework governs the security of systems that command physical equipment — so it's the disciplined method that ensures those physical-consequence systems get security proportional to their risk, and keep it. This AHA frames that governing process rather than the individual technical measures.

Three concerns carry the plan: the RMF process itself, its application to physical-consequence facility control systems, and the lifecycle authorization and governance.

  • Categorize each facility control system by its risk and impact
  • Select the security controls appropriate to that categorization
  • Implement the selected controls (the DDC/SCADA measures)
  • Assess the controls to confirm they're effective
  • Authorize the system to operate based on the accepted risk
  • Continuously monitor the system and its controls over its life

The hazards step by step

The RMF process

The framework is a structured, repeatable process rather than an ad-hoc effort. It categorizes each system by the impact a compromise would have, selects a baseline of security controls matched to that impact, implements them, assesses whether they're working, formally authorizes the system to operate with its residual risk accepted by a responsible authority, and then continuously monitors. This sequence turns security from a guess into a defensible, documented decision: each system gets protection proportional to its risk, chosen and verified through a consistent method. So the value is the discipline and traceability — knowing why each system has the controls it has, and being able to show it.

The application to physical-consequence control systems

Applying the RMF to facility-related control systems is distinctive because these systems command physical equipment, so the "impact" being categorized includes physical and safety consequences, not just data loss. A control system whose compromise could disable safety systems, damage equipment, or endanger occupants is categorized accordingly — higher impact, stronger controls. So the framework's risk categorization has to account for the mechanical and human consequences that set control systems apart from ordinary IT. This is what makes an RMF for facility control systems its own topic: the same process, applied where the stakes are physical.

The lifecycle, authorization, and governance

The framework is a lifecycle, not a one-time event, with formal governance. Authorization is a deliberate decision by a responsible authority to accept a system's residual risk and permit it to operate — a governance step that assigns accountability. And continuous monitoring keeps the security current as the system, threats, and vulnerabilities change, feeding back into re-authorization over time. So roles and responsibilities are defined, the process repeats over the system's life, and security is governed rather than left to drift. The lifecycle and authorization are what keep the protection from decaying after go-live.

The coordination, standards, and control-system fundamentals

Coordination among the facility, IT, security, and authorizing stakeholders, the governing RMF standard and the control-system security measures it selects, and the integrated-automation and control-system fundamentals apply.

A simple Risk Management Framework AHA structure

StepPurposeActivityReference
CategorizeMatch protection to riskAssess impact (incl. physical/safety) of compromiseRMF
Select/implementApply right controlsChoose and put in place appropriate security controlsRMF
AssessConfirm effectivenessVerify the controls workRMF
AuthorizeAccept residual riskResponsible authority permits operationRMF
MonitorKeep currentContinuously monitor and re-authorize over lifeRMF

Where the process governs the measures

This framework is the governing process behind the specific cybersecurity measures — it decides which controls a given facility control system needs, verifies them, authorizes the system, and maintains the protection. So where the DDC and SCADA docs describe what to do technically, this one describes how those decisions are made, justified, and sustained. Applied to physical-consequence control systems, it ensures the security is proportional, accountable, and enduring rather than arbitrary or one-time. The process is the discipline that ties the measures together.

From the field: what actually goes wrong

The failures here are process failures. Security applied without a risk basis — the same generic controls everywhere, too much for some systems and too little for the critical ones — because no categorization was done. Systems put into operation without a formal authorization, so no one accountable ever accepted the risk. And, most common, no continuous monitoring, so the security assessed once at authorization decays as the system and threats change, and the framework becomes a paperwork exercise that doesn't reflect reality. The lessons: categorize each system by its real impact including physical consequences, select and implement controls to match, assess and formally authorize with accountable ownership, and — crucially — monitor continuously so the protection stays current and the framework stays real.

The bottom line

A Risk Management Framework for Facility-Related Control Systems AHA is about the governing process, not the individual measures: categorize each control system by its risk (including physical and safety consequences), select and implement matching controls, assess and formally authorize with accountable ownership, and monitor continuously. Applied to systems that command physical equipment, it ensures their security is proportional, accountable, and sustained. The DDC and SCADA cybersecurity docs are the measures this framework selects and governs.

Frequently asked questions

What is the Risk Management Framework?

It's a structured, lifecycle process for managing cybersecurity risk — most recognizably the NIST Risk Management Framework (RMF). Rather than applying security ad hoc, it follows defined steps: categorize the system by the impact a compromise would have, select a baseline of security controls matched to that impact, implement them, assess whether they're effective, formally authorize the system to operate (with a responsible authority accepting the residual risk), and continuously monitor the system and its controls over time. So it makes security a risk-based, documented, repeatable decision. Applied to facility-related control systems, it's the governing process that decides and maintains the cybersecurity measures (like those in the DDC and SCADA docs) for each system based on its risk.

Why apply a risk framework specifically to facility control systems?

Because facility control systems command physical equipment, so the "impact" that drives the risk decisions includes physical and safety consequences, not just information loss — which changes how they're categorized and protected. A control system whose compromise could disable safeties, damage equipment, or endanger occupants warrants stronger protection, and the framework's categorization has to capture that. Facility and industrial control systems also have characteristics (real-time operation, legacy devices, physical processes) that differ from ordinary IT, so applying the framework thoughtfully to them matters. So a risk framework for facility control systems isn't just generic IT risk management — it's the process adapted to systems whose compromise has mechanical and human consequences, ensuring their security reflects those stakes.

Why is authorization and continuous monitoring emphasized?

Because they're what make the framework a real, sustained governance process rather than a one-time exercise. Authorization is a deliberate decision by a responsible, accountable authority to accept a system's residual risk and permit it to operate — so someone owns the risk decision, rather than a system quietly going live with no one accountable. Continuous monitoring keeps the security current: systems, threats, and vulnerabilities change, so a system secure at authorization drifts into exposure if it's not monitored and periodically re-authorized. So authorization assigns accountability and monitoring maintains the protection over the system's life. Without them, the framework becomes paperwork done once and forgotten — which is the common failure mode. Together they keep the security accountable and enduring.

How does this relate to the specific cybersecurity docs?

This framework is the governing process; the DDC and SCADA cybersecurity docs are the specific measures. The framework decides — for each facility control system, based on its risk — which security controls are needed, then those controls are the technical measures the DDC and SCADA docs describe (network segmentation, hardening, access control, patching, and so on). The framework then verifies the controls, authorizes the system, and monitors. So this doc is the "how we decide and govern" and the cybersecurity docs are the "what we do technically." Together they form the Division 25 cybersecurity picture: the risk-based process that selects and sustains the protection, and the measures that implement it on the direct-digital and supervisory control systems.


Written by Mustafa Tok, CSP, ASP, CHST — OSHA Authorized Outreach Trainer with 14+ years of international construction safety experience across federal, heavy civil, and industrial projects.