1 Scope
This document gives guidelines for the application of principles and a process for
a complexity assessment of an organization’s systems to improve security and resilience. A complexity assessment process allows an organization to identify potential hidden vulnerabilities
of its system and to provide an early indication of risk resulting from complexity .
This document is generic and applicable to all sizes and types of organization systems,
such as critical assets, strategic networks, supply chains, industrial plants, community
infrastructures, banks and business companies.