ICS Security Standards and Compliance Frameworks 3 — Questions and Answers
Question 1: What does the Purdue Enterprise Reference Architecture (PERA) model primarily define for ICS environments?
- Vendor selection criteria
- A hierarchical network segmentation model (Correct answer)
- Incident response procedures
- Employee security training requirements
Correct answer: A hierarchical network segmentation model
The Purdue model defines a hierarchical, layered architecture (Levels 0-5) for segmenting ICS networks from enterprise IT networks.
Question 2: Under ISA/IEC 62443-3-3, System Requirement 3 (SR 3.3) addresses which security capability?
- User authentication
- Security event logging
- Software and information integrity (Correct answer)
- Network access control
Correct answer: Software and information integrity
SR 3.3 in IEC 62443-3-3 requires the system to validate the integrity of software, firmware, and stored information to detect unauthorized changes.
Question 3: Which federal regulation requires cybersecurity programs for pipeline facilities, including ICS/SCADA systems?
- TSA Pipeline Security Directives (Correct answer)
- EPA RMP Rule
- FERC Order 887
- DOT PHMSA Regulations
Correct answer: TSA Pipeline Security Directives
The TSA Pipeline Security Directives (issued 2021-2022) mandate cybersecurity measures including network segmentation and access controls for critical pipeline operators.
Question 4: In the context of NERC CIP, what is a 'Transient Cyber Asset' (TCA)?
- A cyber asset that moves between high and low impact facilities
- A cyber asset connected for 30 days or fewer that can affect BES cyber systems (Correct answer)
- A wireless device used temporarily in the control room
- A backup cyber asset activated during emergencies
Correct answer: A cyber asset connected for 30 days or fewer that can affect BES cyber systems
NERC CIP defines a Transient Cyber Asset as one that is capable of transmitting or transferring data, connected for 30 consecutive days or fewer, and not a BES cyber asset itself.
Question 5: Which IEC 62443 document part specifically provides guidance on the Security Development Lifecycle (SDL) for product suppliers?
- IEC 62443-2-1
- IEC 62443-3-3
- IEC 62443-4-1 (Correct answer)
- IEC 62443-1-1
Correct answer: IEC 62443-4-1
IEC 62443-4-1 defines the Secure Product Development Lifecycle (SDL) requirements that product suppliers must follow during design, development, and maintenance.
Question 6: What is the primary purpose of a Security Management System (CSMS) as defined in IEC 62443-2-1?
- To provide technical specifications for firewall configurations
- To establish policies, procedures, and practices for managing IACS security (Correct answer)
- To define hardware requirements for secure PLCs
- To certify third-party vendors for ICS components
Correct answer: To establish policies, procedures, and practices for managing IACS security
IEC 62443-2-1 defines a Cybersecurity Management System (CSMS) as the overall framework of policies, processes, and procedures an organization uses to manage IACS security.
Question 7: Which NIST SP 800-82 revision introduced specific guidance for cloud-based OT systems and IoT/IIoT devices?
- Revision 1 (2011)
- Revision 2 (2015)
- Revision 3 (2023) (Correct answer)
- Original publication (2006)
Correct answer: Revision 3 (2023)
NIST SP 800-82 Revision 3 (2023) significantly expanded coverage to include cloud-based OT, IoT/IIoT, and modern threats not addressed in earlier revisions.
What does the Purdue Enterprise Reference Architecture (PERA) model primarily define for ICS environments?