Security Standards and Compliance Frameworks Flashcards
7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Standards and Compliance Frameworks flashcards as text
Which NERC CIP standard specifically addresses Electronic Security Perimeters (ESPs) for bulk electric system cyber assets?
Answer: NERC CIP-005
NERC CIP-005 defines requirements for identifying and protecting Electronic Security Perimeters around high and medium impact BES cyber systems.
The IEC 62443 standard series addresses security for which type of systems?
Answer: Industrial Automation and Control Systems (IACS)
IEC 62443 is the international standard series specifically developed for Industrial Automation and Control Systems (IACS) security.
Under NIST SP 800-82, which security zone concept involves grouping OT assets with similar security requirements?
Answer: Security zones and conduits
NIST SP 800-82 adopts IEC 62443's zones and conduits concept to group OT assets by security requirements and manage inter-zone communications.
Which compliance framework mandates that critical infrastructure owners report significant cybersecurity incidents to CISA within 72 hours?
Answer: CIRCIA
The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) requires covered entities to report significant cyber incidents to CISA within 72 hours.
In IEC 62443, what term describes the maximum tolerable level of security risk for a given system or zone?
Answer: Target Security Level (SL-T)
The Target Security Level (SL-T) in IEC 62443 defines the desired security level that a zone or conduit must achieve based on risk assessment.
Which NIST framework function focuses on developing organizational understanding to manage cybersecurity risk?
Answer: Identify
The Identify function of the NIST Cybersecurity Framework involves understanding the organization's assets, business environment, governance, risk, and vulnerabilities.
Which NERC CIP standard requires utilities to implement a patch management process for BES cyber systems?
Answer: CIP-007
NERC CIP-007 (Systems Security Management) requires utilities to implement security patch management programs for BES cyber systems.