Emergency Response Procedures Flashcards
7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Emergency Response Procedures flashcards as text
During an ICS security incident, what is the PRIMARY purpose of an Incident Response Plan (IRP)?
Answer: To provide structured steps for detecting, containing, and recovering from incidents
An IRP provides a structured, pre-defined set of procedures to detect, contain, eradicate, and recover from security incidents in a consistent and timely manner.
Which containment strategy is MOST appropriate when an ICS operator workstation is suspected of malware infection during active production?
Answer: Isolate the workstation from the network while maintaining manual process control
Network isolation of the suspected workstation limits malware spread while allowing manual control to maintain safety and production continuity.
In ICS emergency response, what does the term 'safe state' refer to?
Answer: A pre-defined operational condition where the physical process poses minimal hazard
A safe state is a pre-engineered operational condition designed to minimize hazard to personnel, equipment, and the environment during an emergency.
When should ICS operators switch from automated control to manual control during a cyber incident?
Answer: When automated systems are confirmed compromised and manual control can maintain safety
Switching to manual control is warranted when automated systems are compromised and human operators can safely maintain process control to prevent harm.
What is the role of Out-of-Band (OOB) communications during an ICS cyber incident?
Answer: To provide a communication channel that is independent of potentially compromised networks
OOB communications (e.g., landlines, satellite phones) allow responders to coordinate without relying on networks that may be compromised.
Which document should define who has the authority to order a controlled shutdown of an ICS during a security emergency?
Answer: The Incident Response Plan or Emergency Response Procedures
The IRP or ERP should explicitly define roles, responsibilities, and authority chains including who can authorize emergency shutdowns.
After containing an ICS cyber incident, what is the NEXT phase in the incident response lifecycle?
Answer: Eradication
Following containment, the eradication phase focuses on removing the threat (malware, attacker access, vulnerabilities) from the environment before recovery begins.