ICS Threat Assessment & Risk Analysis 3 — Questions and Answers
Question 1: In the context of ICS threat assessment, what does 'consequence severity' for a safety instrumented system (SIS) failure primarily measure?
- Financial cost of system downtime
- Potential for physical harm, environmental damage, or loss of life (Correct answer)
- Number of systems affected by the failure
- Time required to restore normal operations
Correct answer: Potential for physical harm, environmental damage, or loss of life
For SIS failures, consequence severity primarily measures potential for physical harm, environmental damage, or loss of life because SIS are the last line of defense against hazardous process conditions.
Question 2: A threat analyst is using ATT&CK for ICS. Which tactic would encompass an adversary sending malicious commands to cause a turbine to operate outside safe parameters?
- Initial Access
- Impair Process Control (Correct answer)
- Discovery
- Lateral Movement
Correct answer: Impair Process Control
ATT&CK for ICS defines 'Impair Process Control' as the tactic covering adversary techniques that manipulate, disable, or damage physical control processes, including sending rogue commands to field devices.
Question 3: Which qualitative risk rating matrix cell represents the HIGHEST risk for a scenario with 'Catastrophic' consequence and 'Almost Certain' likelihood?
- Medium
- High
- Critical
- Extreme (Correct answer)
Correct answer: Extreme
The intersection of 'Catastrophic' consequence and 'Almost Certain' likelihood in a standard 5×5 risk matrix yields an 'Extreme' rating, requiring immediate treatment.
Question 4: When assessing threats to an ICS, what distinguishes a 'capability' from a 'motivation' in threat actor characterization?
- Capability is why the actor attacks; motivation is what tools they use
- Capability is the technical skill and resources available; motivation is the reason for attacking (Correct answer)
- Capability refers to legal authority; motivation refers to financial resources
- Capability is the number of personnel; motivation is geographic origin
Correct answer: Capability is the technical skill and resources available; motivation is the reason for attacking
In threat actor characterization, capability describes the technical skills, tools, and resources an actor possesses, while motivation describes the underlying reason or goal driving the attack.
Question 5: An oil refinery conducts a Process Hazard Analysis (PHA). How does PHA relate to an ICS cybersecurity risk assessment?
- PHA replaces the need for a cybersecurity risk assessment
- PHA identifies physical process hazards that cybersecurity attacks could trigger, informing consequence analysis (Correct answer)
- PHA is performed only after a cybersecurity incident occurs
- PHA focuses exclusively on equipment failure, not cyber threats
Correct answer: PHA identifies physical process hazards that cybersecurity attacks could trigger, informing consequence analysis
PHA identifies physical process hazards and their consequences, providing critical input to cybersecurity risk assessments by defining what physical outcomes a successful cyberattack could cause.
Question 6: What is 'attack surface' specifically referring to in an ICS threat assessment?
- The total number of employees with system access
- All points where an unauthorized user could attempt to enter or extract data from the system (Correct answer)
- The geographic footprint of all ICS assets
- The maximum bandwidth available on the OT network
Correct answer: All points where an unauthorized user could attempt to enter or extract data from the system
Attack surface refers to all potential entry and exit points that an adversary could exploit, including network interfaces, remote access channels, removable media ports, and engineering workstations in an ICS environment.
Question 7: In ICS risk assessments, the concept of 'risk appetite' is best described as:
- The maximum financial budget allocated for cybersecurity controls
- The level of risk an organization is willing to accept after controls are applied (Correct answer)
- The number of vulnerabilities deemed acceptable before patching is required
- The frequency of risk assessments mandated by regulators
Correct answer: The level of risk an organization is willing to accept after controls are applied
Risk appetite defines the amount and type of residual risk an organization is willing to tolerate in pursuit of its objectives, serving as the benchmark for deciding when additional controls are needed.
In the context of ICS threat assessment, what does 'consequence severity' for a safety instrumented system (SIS) failure primarily measure?