โ† All ICS Flashcard Decks

Report Writing & Documentation Flashcards

7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Report Writing & Documentation flashcards as text
  1. When documenting an ICS incident, what is the primary purpose of a chain-of-custody log?

    Answer: To track who accessed or handled evidence to preserve its integrity

    Chain-of-custody logs ensure evidence integrity by recording every person who handled evidence, which is critical for legal proceedings.

  2. Which section of an ICS security assessment report typically describes the methodology and tools used during testing?

    Answer: Assessment Methodology

    The Assessment Methodology section details the techniques, tools, and procedures used so stakeholders can evaluate the assessment's rigor.

  3. A security analyst must report a vulnerability in a SCADA system to a federal regulator. Which document format is most appropriate?

    Answer: Structured incident report following NERC CIP or sector-specific regulatory template

    Federal regulatory submissions require structured formats aligned with applicable standards like NERC CIP to ensure completeness and legal compliance.

  4. What does 'impact assessment' mean in the context of an ICS security report?

    Answer: Evaluating how a vulnerability or incident affects safety, operations, and data integrity

    Impact assessment evaluates the operational, safety, and data-integrity consequences of a security event to prioritize response and remediation.

  5. Which element is MOST critical to include when documenting ICS network topology changes for audit purposes?

    Answer: Date, authorized approver, and before/after configuration details

    Audit-ready change documentation must include timestamps, authorization records, and configuration deltas to establish accountability.

  6. In an ICS incident report, a 'lessons-learned' section primarily serves what purpose?

    Answer: To document future improvement actions and prevent recurrence

    Lessons-learned sections capture actionable improvements so the organization can strengthen defenses and processes after an incident.

  7. When writing an executive summary for an ICS security assessment, the language should be:

    Answer: Concise, risk-focused, and free of excessive jargon for non-technical decision-makers

    Executive summaries target leadership who need clear risk context and business impact without deep technical detail.