ICS Legal Authority & Use of Force 2 — Questions and Answers
Question 1: Under the Computer Fraud and Abuse Act (CFAA), which action by an ICS security professional would most likely constitute unauthorized access?
- Scanning an ICS network segment not covered by their written authorization (Correct answer)
- Reviewing firewall logs on systems they are assigned to protect
- Applying patches during an approved maintenance window
- Responding to an active intrusion on their own protected network
Correct answer: Scanning an ICS network segment not covered by their written authorization
The CFAA prohibits accessing computer systems without authorization, including ICS segments outside the scope defined in a written authorization agreement.
Question 2: Which federal law primarily governs cybersecurity requirements for critical infrastructure, including ICS environments, in the United States?
- HIPAA
- FISMA
- CISA 2022 (Cyber Incident Reporting for Critical Infrastructure Act) (Correct answer)
- Sarbanes-Oxley Act
Correct answer: CISA 2022 (Cyber Incident Reporting for Critical Infrastructure Act)
CIRCIA 2022 established mandatory cyber incident reporting requirements for critical infrastructure sectors, including those operating ICS environments.
Question 3: A private security guard at a water treatment plant discovers an unauthorized person tampering with PLCs. Under what legal principle may the guard physically detain the individual?
- Sovereign immunity
- Citizen's arrest authority under state law (Correct answer)
- Federal law enforcement deputization
- NERC CIP enforcement authority
Correct answer: Citizen's arrest authority under state law
Private security personnel may detain individuals under citizen's arrest provisions of applicable state law when witnessing a crime in progress.
Question 4: Which document formally defines the scope and limitations of a penetration tester's authority to test an ICS environment?
- Security policy
- Rules of Engagement (ROE) (Correct answer)
- Memorandum of Understanding (MOU)
- Service Level Agreement (SLA)
Correct answer: Rules of Engagement (ROE)
Rules of Engagement define the specific boundaries, methods, and limitations authorized for a penetration test, providing legal protection for the tester.
Question 5: An ICS operator at a power substation uses force to stop a physical intruder from accessing the control room. Which legal standard typically governs whether the force used was justified?
- The intruder must have been armed
- Force must be proportional to the threat presented (Correct answer)
- Only law enforcement may use force in critical infrastructure
- Any amount of force is permitted to protect critical infrastructure
Correct answer: Force must be proportional to the threat presented
The proportionality doctrine requires that the level of force used be reasonably proportional to the level of threat posed by the intruder.
Question 6: Under NERC CIP standards, what is the primary purpose of physical security controls at Electronic Security Perimeters (ESPs)?
- To authorize use of lethal force against intruders
- To restrict and monitor access to cyber assets within the perimeter (Correct answer)
- To establish jurisdiction for federal law enforcement
- To define liability limits for security personnel
Correct answer: To restrict and monitor access to cyber assets within the perimeter
NERC CIP ESP requirements focus on restricting and logging access to cyber assets to prevent unauthorized access, not on authorizing force.
Question 7: Which government agency has primary authority to investigate cybersecurity incidents affecting U.S. critical infrastructure ICS systems?
- Department of Energy (DOE)
- Cybersecurity and Infrastructure Security Agency (CISA) (Correct answer)
- National Security Agency (NSA)
- Federal Trade Commission (FTC)
Correct answer: Cybersecurity and Infrastructure Security Agency (CISA)
CISA is the lead federal agency for coordinating cybersecurity efforts and incident response across U.S. critical infrastructure sectors.
Under the Computer Fraud and Abuse Act (CFAA), which action by an ICS security professional would most likely constitute unauthorized access?