ICS Report Writing & Documentation 2 — Questions and Answers
Question 1: When documenting an ICS incident, what is the primary purpose of a chain-of-custody log?
- To list all personnel who responded to the incident
- To track who accessed or handled evidence to preserve its integrity (Correct answer)
- To record the timeline of system downtime
- To document vendor notifications during the incident
Correct answer: To track who accessed or handled evidence to preserve its integrity
Chain-of-custody logs ensure evidence integrity by recording every person who handled evidence, which is critical for legal proceedings.
Question 2: Which section of an ICS security assessment report typically describes the methodology and tools used during testing?
- Executive Summary
- Scope and Objectives
- Assessment Methodology (Correct answer)
- Findings and Recommendations
Correct answer: Assessment Methodology
The Assessment Methodology section details the techniques, tools, and procedures used so stakeholders can evaluate the assessment's rigor.
Question 3: A security analyst must report a vulnerability in a SCADA system to a federal regulator. Which document format is most appropriate?
- Informal email with bullet points
- Structured incident report following NERC CIP or sector-specific regulatory template (Correct answer)
- Oral briefing with no written follow-up
- Internal wiki entry
Correct answer: Structured incident report following NERC CIP or sector-specific regulatory template
Federal regulatory submissions require structured formats aligned with applicable standards like NERC CIP to ensure completeness and legal compliance.
Question 4: What does 'impact assessment' mean in the context of an ICS security report?
- Estimating the cost of new security hardware
- Evaluating how a vulnerability or incident affects safety, operations, and data integrity (Correct answer)
- Measuring network throughput after a patch is applied
- Counting the number of affected workstations
Correct answer: Evaluating how a vulnerability or incident affects safety, operations, and data integrity
Impact assessment evaluates the operational, safety, and data-integrity consequences of a security event to prioritize response and remediation.
Question 5: Which element is MOST critical to include when documenting ICS network topology changes for audit purposes?
- Color-coded diagram aesthetics
- Date, authorized approver, and before/after configuration details (Correct answer)
- Vendor marketing brochures for new equipment
- Number of engineers who reviewed the change
Correct answer: Date, authorized approver, and before/after configuration details
Audit-ready change documentation must include timestamps, authorization records, and configuration deltas to establish accountability.
Question 6: In an ICS incident report, a 'lessons-learned' section primarily serves what purpose?
- To assign blame to personnel who made errors
- To document future improvement actions and prevent recurrence (Correct answer)
- To satisfy a legal discovery requirement
- To list all software licenses used during response
Correct answer: To document future improvement actions and prevent recurrence
Lessons-learned sections capture actionable improvements so the organization can strengthen defenses and processes after an incident.
Question 7: When writing an executive summary for an ICS security assessment, the language should be:
- Highly technical with full protocol details and packet captures
- Concise, risk-focused, and free of excessive jargon for non-technical decision-makers (Correct answer)
- Limited to a single sentence summarizing the overall risk score
- Written entirely in passive voice to avoid assigning responsibility
Correct answer: Concise, risk-focused, and free of excessive jargon for non-technical decision-makers
Executive summaries target leadership who need clear risk context and business impact without deep technical detail.
When documenting an ICS incident, what is the primary purpose of a chain-of-custody log?