ICS Report Writing & Documentation 3 â Questions and Answers
Question 1: What is the recommended practice for classifying sensitive ICS security reports?
- Share all reports publicly to promote transparency
- Apply classification labels (e.g., Confidential, Restricted) and limit distribution on a need-to-know basis (Correct answer)
- Store reports unencrypted on shared network drives for easy access
- Classify all reports as 'Top Secret' regardless of content
Correct answer: Apply classification labels (e.g., Confidential, Restricted) and limit distribution on a need-to-know basis
Sensitive ICS reports should carry appropriate classification markings and be distributed only to personnel who require the information to perform their duties.
Question 2: Which of the following BEST describes a 'finding' in an ICS vulnerability assessment report?
- A general description of the ICS environment
- A specific identified weakness, its evidence, risk rating, and recommended remediation (Correct answer)
- A summary of all assets scanned during the assessment
- A list of personnel interviewed during the review
Correct answer: A specific identified weakness, its evidence, risk rating, and recommended remediation
A finding presents a specific vulnerability with supporting evidence, a risk rating, and actionable remediation guidance.
Question 3: What is the purpose of a 'risk register' in ICS security documentation?
- To list all employees with system access
- To maintain a centralized log of identified risks, their likelihood, impact, and mitigation status (Correct answer)
- To record daily system backups
- To track software licensing compliance
Correct answer: To maintain a centralized log of identified risks, their likelihood, impact, and mitigation status
A risk register provides a living document that tracks each identified risk, enabling management to monitor mitigation progress over time.
Question 4: During post-incident documentation for an ICS breach, which timeline artifact is most valuable for forensic reconstruction?
- Vendor invoice for replacement parts
- System and network log timestamps correlated to event sequence (Correct answer)
- Number of help desk tickets submitted during the incident
- Marketing emails sent to customers about service disruption
Correct answer: System and network log timestamps correlated to event sequence
Correlated log timestamps allow analysts to reconstruct the exact sequence of events, which is foundational to forensic investigation.
Question 5: An ICS security report recommends patching a critical PLC firmware vulnerability. The recommendation should include:
- Only the patch version number
- Risk rating, patch steps, testing requirements, rollback plan, and responsible party (Correct answer)
- A general statement that firmware should be kept current
- The vendor's full product catalog
Correct answer: Risk rating, patch steps, testing requirements, rollback plan, and responsible party
Actionable recommendations must include enough detailârisk context, steps, testing, rollback, and ownershipâfor safe implementation in an ICS environment.
Question 6: Which standard provides guidance specifically for documenting ICS security controls and assessments in the US federal context?
- ISO 9001
- NIST SP 800-82 (Correct answer)
- OSHA 1910.119
- IEEE 802.11
Correct answer: NIST SP 800-82
NIST SP 800-82 (Guide to ICS Security) provides US federal guidance on securing and documenting ICS, including assessment and reporting practices.
Question 7: When should an ICS incident report be marked as 'draft' versus 'final'?
- Draft is used only when the author is unsatisfied with the content
- Draft indicates the report is under review and not yet formally approved; final indicates it has passed approval (Correct answer)
- Final reports are only issued after litigation is complete
- Draft and final labels have no meaningful distinction in ICS reporting
Correct answer: Draft indicates the report is under review and not yet formally approved; final indicates it has passed approval
Draft status signals the report is still being reviewed or verified, while final status indicates formal approval and release to appropriate stakeholders.
What is the recommended practice for classifying sensitive ICS security reports?