ICS Legal Authority & Use of Force 3 — Questions and Answers
Question 1: A chemical plant security team receives a court order to preserve all digital evidence from a compromised HMI. Which legal doctrine requires them to halt normal log-rotation procedures?
- Chain of custody
- Legal hold (litigation hold) (Correct answer)
- Right to audit
- Duty to warn
Correct answer: Legal hold (litigation hold)
A legal hold requires an organization to suspend normal data destruction or alteration processes to preserve evidence relevant to anticipated or active litigation.
Question 2: Which concept describes the documented, unbroken transfer of evidence from an ICS incident scene to the courtroom?
- Due process
- Evidentiary privilege
- Chain of custody (Correct answer)
- Probable cause
Correct answer: Chain of custody
Chain of custody documents every person who handled evidence and every location it was stored, ensuring its integrity is not challenged in court.
Question 3: A security professional conducting ICS vulnerability assessments for a U.S. federal agency must comply with which overarching federal information security law?
- FISMA (Federal Information Security Modernization Act) (Correct answer)
- COPPA
- GLBA
- CCPA
Correct answer: FISMA (Federal Information Security Modernization Act)
FISMA establishes requirements for information security programs at federal agencies and contractors handling federal information, including ICS systems.
Question 4: In an ICS environment, what is the minimum requirement before security personnel may use force to defend against a cyberattack causing physical harm?
- Approval from the facility CISO
- Imminent threat of serious bodily harm or death must exist (Correct answer)
- A signed executive order must be in place
- Law enforcement must be notified first
Correct answer: Imminent threat of serious bodily harm or death must exist
Use of physical force in defense against a cyberattack causing physical effects is governed by standard self-defense law requiring an imminent threat of serious harm.
Question 5: Which international framework addresses the law of armed conflict as it applies to cyber operations targeting critical infrastructure like ICS?
- Budapest Convention
- Tallinn Manual (Correct answer)
- ISO 27001
- UN Charter Article 2
Correct answer: Tallinn Manual
The Tallinn Manual is a non-binding expert analysis that applies international humanitarian law and laws of armed conflict to cyber operations, including attacks on critical infrastructure.
Question 6: An energy company's ICS security team wants to 'hack back' against an attacker targeting their SCADA systems. Which U.S. law most directly prohibits this?
- Electronic Communications Privacy Act
- Computer Fraud and Abuse Act (CFAA) (Correct answer)
- National Security Act
- USA PATRIOT Act
Correct answer: Computer Fraud and Abuse Act (CFAA)
The CFAA prohibits unauthorized access to computer systems, and hack-back operations against an attacker's infrastructure constitute unauthorized access under this law.
Question 7: A private security officer at a natural gas compressor station may use deadly force ONLY when:
- An intruder is spotted inside the outer perimeter fence
- A supervisor authorizes it verbally
- The officer reasonably believes there is an imminent threat of death or serious bodily injury (Correct answer)
- The intruder refuses to show identification
Correct answer: The officer reasonably believes there is an imminent threat of death or serious bodily injury
Deadly force is legally justified only when the officer has a reasonable belief of imminent threat of death or serious bodily injury, consistent with state use-of-force statutes.
A chemical plant security team receives a court order to preserve all digital evidence from a compromised HMI.
Which legal doctrine requires them to halt normal log-rotation procedures?