ICS Security Risk Management and Incident Response 5 — Questions and Answers
Question 1: The concept of 'tabletop exercises' in ICS incident response refers to:
- Physical dismantling of ICS equipment to test hardware resilience
- Discussion-based simulations where participants walk through an incident scenario without activating actual response procedures (Correct answer)
- Automated testing of ICS backup and recovery systems
- Penetration testing conducted on a physical replica of the ICS environment
Correct answer: Discussion-based simulations where participants walk through an incident scenario without activating actual response procedures
Tabletop exercises use scenario-based discussions to evaluate the incident response plan, test decision-making, and identify gaps without disrupting live operations.
Question 2: When an ICS organization transfers risk by purchasing cyber insurance, which residual obligation remains?
- No further action is required since the risk is fully transferred
- The organization must still implement reasonable security controls as required by the insurance policy (Correct answer)
- The organization transfers both financial and operational responsibility to the insurer
- Insurance eliminates the need for incident response planning
Correct answer: The organization must still implement reasonable security controls as required by the insurance policy
Cyber insurance policies require the insured to maintain minimum security standards; failing to do so can void coverage, meaning organizations still must manage the risk.
Question 3: Which metric BEST measures the effectiveness of an ICS incident response program over time?
- Number of security policies documented and approved
- Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) trends across incidents (Correct answer)
- Total number of security tools deployed in the OT environment
- Number of employees who completed annual security awareness training
Correct answer: Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) trends across incidents
MTTD and MTTR measure how quickly threats are detected and contained, directly reflecting the operational effectiveness of the incident response program.
Question 4: During the 'eradication' phase of ICS incident response, the primary goal is to:
- Preserve and collect forensic evidence before making any changes
- Remove all traces of the attacker and eliminate the root cause from affected systems (Correct answer)
- Restore systems to full production capacity as quickly as possible
- Notify regulatory bodies and affected third parties about the incident
Correct answer: Remove all traces of the attacker and eliminate the root cause from affected systems
Eradication focuses on removing malware, closing attack vectors, and eliminating the root cause to prevent reinfection before recovery begins.
Question 5: A facility uses the MITRE ATT&CK for ICS framework during incident response. Its primary value is:
- Providing regulatory compliance checklists for ICS security programs
- Offering a common taxonomy of adversary tactics, techniques, and procedures (TTPs) specific to ICS environments (Correct answer)
- Automating threat detection through signature-based intrusion detection rules
- Replacing the need for manual threat hunting in OT environments
Correct answer: Offering a common taxonomy of adversary tactics, techniques, and procedures (TTPs) specific to ICS environments
MITRE ATT&CK for ICS provides a structured knowledge base of ICS-specific adversary behaviors, enabling teams to map observed activity to known attack patterns.
Question 6: In the context of ICS risk management, 'inherent risk' is best defined as:
- The risk level after all security controls have been fully implemented
- The raw risk level that exists before any controls or mitigations are applied (Correct answer)
- The risk accepted by senior management after reviewing the risk register
- The risk transferred to third parties through contracts or insurance
Correct answer: The raw risk level that exists before any controls or mitigations are applied
Inherent risk represents the natural exposure to a threat before any security controls are applied, establishing the baseline for risk treatment decisions.
Question 7: An ICS organization must notify the Department of Homeland Security (DHS) CISA about a significant cyber incident within 72 hours under which regulation?
- NERC CIP-008
- CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) (Correct answer)
- ISA/IEC 62443-2-1
- NIST SP 800-61
Correct answer: CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
CIRCIA requires critical infrastructure entities to report significant cyber incidents to CISA within 72 hours and ransom payments within 24 hours.
The concept of 'tabletop exercises' in ICS incident response refers to: