โ† All ICS Flashcard Decks

Security Standards and Compliance Frameworks Flashcards

7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Standards and Compliance Frameworks flashcards as text
  1. Which NERC CIP standard specifically addresses Electronic Security Perimeters (ESPs) for bulk electric system cyber assets?

    Answer: NERC CIP-005

    NERC CIP-005 defines requirements for identifying and protecting Electronic Security Perimeters around high and medium impact BES cyber systems.

  2. The IEC 62443 standard series addresses security for which type of systems?

    Answer: Industrial Automation and Control Systems (IACS)

    IEC 62443 is the international standard series specifically developed for Industrial Automation and Control Systems (IACS) security.

  3. Under NIST SP 800-82, which security zone concept involves grouping OT assets with similar security requirements?

    Answer: Security zones and conduits

    NIST SP 800-82 adopts IEC 62443's zones and conduits concept to group OT assets by security requirements and manage inter-zone communications.

  4. Which compliance framework mandates that critical infrastructure owners report significant cybersecurity incidents to CISA within 72 hours?

    Answer: CIRCIA

    The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) requires covered entities to report significant cyber incidents to CISA within 72 hours.

  5. In IEC 62443, what term describes the maximum tolerable level of security risk for a given system or zone?

    Answer: Target Security Level (SL-T)

    The Target Security Level (SL-T) in IEC 62443 defines the desired security level that a zone or conduit must achieve based on risk assessment.

  6. Which NIST framework function focuses on developing organizational understanding to manage cybersecurity risk?

    Answer: Identify

    The Identify function of the NIST Cybersecurity Framework involves understanding the organization's assets, business environment, governance, risk, and vulnerabilities.

  7. Which NERC CIP standard requires utilities to implement a patch management process for BES cyber systems?

    Answer: CIP-007

    NERC CIP-007 (Systems Security Management) requires utilities to implement security patch management programs for BES cyber systems.