Legal Authority & Use of Force Flashcards
7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Legal Authority & Use of Force flashcards as text
Under the Computer Fraud and Abuse Act (CFAA), which action by an ICS security professional would most likely constitute unauthorized access?
Answer: Scanning an ICS network segment not covered by their written authorization
The CFAA prohibits accessing computer systems without authorization, including ICS segments outside the scope defined in a written authorization agreement.
Which federal law primarily governs cybersecurity requirements for critical infrastructure, including ICS environments, in the United States?
Answer: CISA 2022 (Cyber Incident Reporting for Critical Infrastructure Act)
CIRCIA 2022 established mandatory cyber incident reporting requirements for critical infrastructure sectors, including those operating ICS environments.
A private security guard at a water treatment plant discovers an unauthorized person tampering with PLCs. Under what legal principle may the guard physically detain the individual?
Answer: Citizen's arrest authority under state law
Private security personnel may detain individuals under citizen's arrest provisions of applicable state law when witnessing a crime in progress.
Which document formally defines the scope and limitations of a penetration tester's authority to test an ICS environment?
Answer: Rules of Engagement (ROE)
Rules of Engagement define the specific boundaries, methods, and limitations authorized for a penetration test, providing legal protection for the tester.
An ICS operator at a power substation uses force to stop a physical intruder from accessing the control room. Which legal standard typically governs whether the force used was justified?
Answer: Force must be proportional to the threat presented
The proportionality doctrine requires that the level of force used be reasonably proportional to the level of threat posed by the intruder.
Under NERC CIP standards, what is the primary purpose of physical security controls at Electronic Security Perimeters (ESPs)?
Answer: To restrict and monitor access to cyber assets within the perimeter
NERC CIP ESP requirements focus on restricting and logging access to cyber assets to prevent unauthorized access, not on authorizing force.
Which government agency has primary authority to investigate cybersecurity incidents affecting U.S. critical infrastructure ICS systems?
Answer: Cybersecurity and Infrastructure Security Agency (CISA)
CISA is the lead federal agency for coordinating cybersecurity efforts and incident response across U.S. critical infrastructure sectors.