Building an asset inventory, a risk register, and a threat model for critical systems before you design a single control.
Every downstream security decision in this program — which zone a device sits in, which controls Module 5's access model applies, how aggressively Module 9's vulnerability program patches — traces back to a risk assessment. This module covers building an accurate asset inventory (the step most programs get wrong first), scoring risk as a function of likelihood and consequence rather than either alone, and threat modeling frameworks like STRIDE and the MITRE ATT&CK for ICS matrix for structuring "what could go wrong and how" against a specific system.
By the end of this module you should be able to build a basic risk register for a facility and defend why one asset ranks above another — the exact groundwork Module 14's three real-project case studies assume you can already do before they add segmentation, hardening, or incident-response detail on top.