ICS Security Risk Management and Incident Response 3 — Questions and Answers
Question 1: The concept of 'defense in depth' applied to ICS risk management means:
- Placing all security controls at the network perimeter
- Implementing multiple overlapping layers of security controls so that failure of one does not compromise the entire system (Correct answer)
- Focusing security resources on the most critical assets only
- Relying on physical security as the primary defense mechanism
Correct answer: Implementing multiple overlapping layers of security controls so that failure of one does not compromise the entire system
Defense in depth uses multiple independent security layers so that if one control fails, others still protect the system, reducing overall risk.
Question 2: During post-incident analysis of an ICS breach, the 'lessons learned' document should primarily focus on:
- Assigning blame to individuals who made mistakes during the incident
- Identifying process improvements, control gaps, and updating the incident response plan (Correct answer)
- Documenting the technical details of the attacker's tools and techniques only
- Calculating the financial cost of the incident for insurance purposes
Correct answer: Identifying process improvements, control gaps, and updating the incident response plan
Lessons learned should drive improvements to processes, controls, and response plans to prevent recurrence and enhance future incident handling.
Question 3: An ICS facility experiences repeated false positives from its intrusion detection system. The BEST long-term risk management approach is:
- Disable the IDS to reduce alert fatigue among operators
- Tune detection signatures and thresholds based on the specific ICS environment's normal behavior baseline (Correct answer)
- Ignore alerts that have been false positives more than three times
- Replace the IDS with a firewall that blocks suspicious traffic automatically
Correct answer: Tune detection signatures and thresholds based on the specific ICS environment's normal behavior baseline
Tuning IDS signatures to match the specific ICS environment's normal operational baseline reduces false positives while maintaining detection effectiveness.
Question 4: Under the ISA/IEC 62443 standard, a Security Level (SL) 3 target means the system must be protected against:
- Accidental or coincidental violations
- Intentional violation using simple means with low motivation and generic skills
- Intentional violation using sophisticated means with moderate resources and IACS-specific skills (Correct answer)
- Intentional violation by a nation-state actor with extensive resources
Correct answer: Intentional violation using sophisticated means with moderate resources and IACS-specific skills
SL 3 addresses threats from sophisticated attackers with ICS-specific skills and moderate resources, such as organized criminal groups or hacktivists with industrial knowledge.
Question 5: Which risk assessment methodology specifically designed for industrial control systems uses a consequence-driven approach focused on 'what bad things could happen'?
- OCTAVE
- FAIR (Factor Analysis of Information Risk)
- CARVER (Criticality, Accessibility, Recuperability, Vulnerability, Effect, Recognizability)
- HAZOP (Hazard and Operability Study) (Correct answer)
Correct answer: HAZOP (Hazard and Operability Study)
HAZOP is a structured, consequence-driven risk assessment method originating from process safety that identifies hazards and operability issues in industrial systems.
Question 6: In ICS incident response, 'scoping' refers to:
- Determining the legal authority to prosecute the attackers
- Defining the boundaries of the incident to understand what systems and data were affected (Correct answer)
- Scheduling the timeline for completing the incident response
- Selecting which security tools will be used during the investigation
Correct answer: Defining the boundaries of the incident to understand what systems and data were affected
Scoping defines the extent of the incident by identifying affected systems, networks, and data to ensure the response effort is appropriately focused and complete.
Question 7: A chemical plant discovers that a historian server was compromised and production data was exfiltrated over 6 months. This scenario BEST illustrates which type of threat?
- Script kiddie attack
- Advanced Persistent Threat (APT) (Correct answer)
- Distributed Denial of Service (DDoS)
- Insider threat from a disgruntled employee
Correct answer: Advanced Persistent Threat (APT)
APTs are characterized by long dwell times, stealth, persistence, and targeted data exfiltration, often conducted by nation-state or sophisticated threat actors.
The concept of 'defense in depth' applied to ICS risk management means: