ICS Security Risk Management and Incident Response 2 — Questions and Answers
Question 1: During an ICS incident, the FIRST priority for the incident response team should be:
- Preserve forensic evidence for later analysis
- Restore normal operations as quickly as possible
- Ensure safety of personnel and prevent physical harm (Correct answer)
- Notify law enforcement and regulatory bodies
Correct answer: Ensure safety of personnel and prevent physical harm
In ICS environments, safety of personnel and prevention of physical harm always takes precedence over other incident response objectives.
Question 2: A risk treatment option where an organization accepts the potential loss from a risk without taking action is called:
- Risk avoidance
- Risk transfer
- Risk acceptance (Correct answer)
- Risk mitigation
Correct answer: Risk acceptance
Risk acceptance (also called risk retention) means the organization acknowledges the risk and decides not to take additional action, often because the cost of mitigation exceeds the potential loss.
Question 3: Which NIST publication provides the primary framework for managing cybersecurity risk in critical infrastructure including ICS?
- NIST SP 800-53
- NIST SP 800-82
- NIST Cybersecurity Framework (CSF) (Correct answer)
- NIST SP 800-37
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) provides a common language and systematic methodology for managing cybersecurity risk across critical infrastructure sectors.
Question 4: In an ICS incident response playbook, a 'runbook' is best described as:
- A log of all actions taken during a previous incident
- Step-by-step procedural instructions for responding to a specific incident type (Correct answer)
- A risk register documenting all known vulnerabilities
- A communication plan for notifying stakeholders
Correct answer: Step-by-step procedural instructions for responding to a specific incident type
A runbook contains detailed, step-by-step instructions for responding to a specific type of incident, enabling consistent and efficient response even under pressure.
Question 5: When calculating residual risk in an ICS environment, which formula is most accurate?
- Residual Risk = Inherent Risk × Vulnerability
- Residual Risk = Inherent Risk − Controls Effectiveness (Correct answer)
- Residual Risk = Threat × Asset Value
- Residual Risk = Impact × Likelihood − Cost of Controls
Correct answer: Residual Risk = Inherent Risk − Controls Effectiveness
Residual risk is the risk that remains after controls have been applied, calculated as inherent risk minus the effectiveness of implemented security controls.
Question 6: A purple team exercise in the context of ICS security primarily involves:
- Only defensive (blue) team members testing detection capabilities
- Red team attackers operating independently without coordination
- Red and blue teams collaborating to improve both attack and defense capabilities simultaneously (Correct answer)
- External auditors assessing compliance with ICS security standards
Correct answer: Red and blue teams collaborating to improve both attack and defense capabilities simultaneously
Purple teaming combines offensive (red) and defensive (blue) team collaboration to maximize knowledge transfer and improve overall security posture.
Question 7: Which incident containment strategy is most appropriate when malware is detected on an ICS engineering workstation still connected to operational technology (OT) networks?
- Immediately shut down the entire plant to prevent spread
- Isolate the workstation by disconnecting it from both IT and OT networks while maintaining physical safety systems (Correct answer)
- Allow the workstation to continue operating while forensic analysis is performed remotely
- Apply patches and antivirus updates immediately without disconnecting
Correct answer: Isolate the workstation by disconnecting it from both IT and OT networks while maintaining physical safety systems
Isolating the compromised workstation from both networks prevents lateral movement while avoiding disruption to physical safety systems that must remain operational.
During an ICS incident, the FIRST priority for the incident response team should be: