← All ICS Flashcard Decks

Report Writing & Documentation Flashcards

7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Report Writing & Documentation flashcards as text
  1. What is the recommended practice for classifying sensitive ICS security reports?

    Answer: Apply classification labels (e.g., Confidential, Restricted) and limit distribution on a need-to-know basis

    Sensitive ICS reports should carry appropriate classification markings and be distributed only to personnel who require the information to perform their duties.

  2. Which of the following BEST describes a 'finding' in an ICS vulnerability assessment report?

    Answer: A specific identified weakness, its evidence, risk rating, and recommended remediation

    A finding presents a specific vulnerability with supporting evidence, a risk rating, and actionable remediation guidance.

  3. What is the purpose of a 'risk register' in ICS security documentation?

    Answer: To maintain a centralized log of identified risks, their likelihood, impact, and mitigation status

    A risk register provides a living document that tracks each identified risk, enabling management to monitor mitigation progress over time.

  4. During post-incident documentation for an ICS breach, which timeline artifact is most valuable for forensic reconstruction?

    Answer: System and network log timestamps correlated to event sequence

    Correlated log timestamps allow analysts to reconstruct the exact sequence of events, which is foundational to forensic investigation.

  5. An ICS security report recommends patching a critical PLC firmware vulnerability. The recommendation should include:

    Answer: Risk rating, patch steps, testing requirements, rollback plan, and responsible party

    Actionable recommendations must include enough detail—risk context, steps, testing, rollback, and ownership—for safe implementation in an ICS environment.

  6. Which standard provides guidance specifically for documenting ICS security controls and assessments in the US federal context?

    Answer: NIST SP 800-82

    NIST SP 800-82 (Guide to ICS Security) provides US federal guidance on securing and documenting ICS, including assessment and reporting practices.

  7. When should an ICS incident report be marked as 'draft' versus 'final'?

    Answer: Draft indicates the report is under review and not yet formally approved; final indicates it has passed approval

    Draft status signals the report is still being reviewed or verified, while final status indicates formal approval and release to appropriate stakeholders.