Report Writing & Documentation Flashcards
7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Report Writing & Documentation flashcards as text
What is the recommended retention period guidance for ICS security incident records under NERC CIP standards?
Answer: 3 years
NERC CIP-008 requires incident response records to be retained for a minimum of three years to support audits and regulatory review.
Which report type would BEST communicate recurring patch management gaps across multiple ICS sites to senior leadership?
Answer: A trend analysis report showing patch compliance rates over time with risk context
Trend analysis reports contextualize recurring gaps over time, giving leadership the risk picture needed to allocate resources and set priorities.
In ICS documentation, a 'network baseline' record serves primarily to:
Answer: Establish normal traffic patterns and configurations so deviations indicating compromise can be detected
A network baseline documents normal behavior, enabling security teams to identify anomalies that may indicate unauthorized activity or compromise.
When writing remediation recommendations for a safety instrumented system (SIS) vulnerability, the analyst must:
Answer: Consult with process safety engineers and account for safety validation requirements before recommending changes
SIS changes require coordination with process safety engineers because unauthorized modifications can compromise safety functions and create hazardous conditions.
Which approach BEST ensures that ICS security documentation remains accurate and up to date over time?
Answer: Establish a formal document review cycle triggered by system changes, incidents, or annual review schedules
A formal review cycle linked to change events and scheduled reviews ensures documentation reflects the current state of the ICS environment.
A cybersecurity analyst is asked to produce a 'gap analysis' report for an ICS against IEC 62443. What does this report primarily contain?
Answer: A comparison of current ICS security controls against IEC 62443 requirements, identifying deficiencies and remediation priorities
A gap analysis compares the current security posture against a standard's requirements and identifies specific shortfalls that must be addressed.
What is the purpose of including an 'asset inventory' section in an ICS security assessment report?
Answer: To demonstrate the completeness of the assessment scope and provide context for findings tied to specific assets
An asset inventory documents what was in scope, allowing readers to map findings to specific devices and understand the assessment's coverage.