← All ICS Flashcard Decks

Threat Assessment & Risk Analysis Flashcards

7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Threat Assessment & Risk Analysis flashcards as text
  1. In the context of ICS threat assessment, what does 'consequence severity' for a safety instrumented system (SIS) failure primarily measure?

    Answer: Potential for physical harm, environmental damage, or loss of life

    For SIS failures, consequence severity primarily measures potential for physical harm, environmental damage, or loss of life because SIS are the last line of defense against hazardous process conditions.

  2. A threat analyst is using ATT&CK for ICS. Which tactic would encompass an adversary sending malicious commands to cause a turbine to operate outside safe parameters?

    Answer: Impair Process Control

    ATT&CK for ICS defines 'Impair Process Control' as the tactic covering adversary techniques that manipulate, disable, or damage physical control processes, including sending rogue commands to field devices.

  3. Which qualitative risk rating matrix cell represents the HIGHEST risk for a scenario with 'Catastrophic' consequence and 'Almost Certain' likelihood?

    Answer: Extreme

    The intersection of 'Catastrophic' consequence and 'Almost Certain' likelihood in a standard 5×5 risk matrix yields an 'Extreme' rating, requiring immediate treatment.

  4. When assessing threats to an ICS, what distinguishes a 'capability' from a 'motivation' in threat actor characterization?

    Answer: Capability is the technical skill and resources available; motivation is the reason for attacking

    In threat actor characterization, capability describes the technical skills, tools, and resources an actor possesses, while motivation describes the underlying reason or goal driving the attack.

  5. An oil refinery conducts a Process Hazard Analysis (PHA). How does PHA relate to an ICS cybersecurity risk assessment?

    Answer: PHA identifies physical process hazards that cybersecurity attacks could trigger, informing consequence analysis

    PHA identifies physical process hazards and their consequences, providing critical input to cybersecurity risk assessments by defining what physical outcomes a successful cyberattack could cause.

  6. What is 'attack surface' specifically referring to in an ICS threat assessment?

    Answer: All points where an unauthorized user could attempt to enter or extract data from the system

    Attack surface refers to all potential entry and exit points that an adversary could exploit, including network interfaces, remote access channels, removable media ports, and engineering workstations in an ICS environment.

  7. In ICS risk assessments, the concept of 'risk appetite' is best described as:

    Answer: The level of risk an organization is willing to accept after controls are applied

    Risk appetite defines the amount and type of residual risk an organization is willing to tolerate in pursuit of its objectives, serving as the benchmark for deciding when additional controls are needed.