SACA Industrial Cybersecurity (OT/ICS Security) — Questions and Answers
Question 1: What is the primary security concern that differentiates Operational Technology (OT) networks from traditional IT networks?
- OT networks transmit larger data volumes and require higher bandwidth protection
- In OT environments, availability and safety are paramount — a security patch or system reboot can halt production or cause physical harm, making patch management far more constrained than in IT (Correct answer)
- OT networks use stronger encryption standards that IT security tools cannot inspect
- OT systems are air-gapped by regulation, so external threats are not a concern
Correct answer: In OT environments, availability and safety are paramount — a security patch or system reboot can halt production or cause physical harm, making patch management far more constrained than in IT
In IT, the CIA triad prioritizes Confidentiality first. In OT/ICS, Availability and Safety come first — a cyber incident that stops a power plant or chemical process can have catastrophic physical consequences. This inverts patch management and security tool deployment strategies compared to IT environments.
Question 2: The Purdue Reference Model (ISA-99) is used in ICS security to:
- Define PLC ladder logic programming standards across vendors
- Segment industrial networks into hierarchical levels (field devices → control → operations → enterprise) to limit lateral movement of threats (Correct answer)
- Specify the encryption algorithms required for SCADA historian databases
- Standardize the physical wiring topology of industrial Ethernet networks
Correct answer: Segment industrial networks into hierarchical levels (field devices → control → operations → enterprise) to limit lateral movement of threats
The Purdue Model divides ICS architecture into levels (Level 0: field devices, Level 1: controllers, Level 2: supervisory/SCADA, Level 3: operations/MES, Level 4: enterprise/IT). Network segmentation between levels — using firewalls and DMZs — limits an attacker's ability to move from the IT network down to process control systems.
Question 3: Which international standard series specifically addresses cybersecurity for Industrial Automation and Control Systems (IACS)?
- IEC 62443 (Correct answer)
- ISO 27001
- NIST SP 800-53
- IEC 61511
Correct answer: IEC 62443
IEC 62443 (formerly ISA-99) is the definitive international standard series for IACS cybersecurity. It covers policies, procedures, system design, and component requirements for securing industrial control systems. ISO 27001 addresses general IT security management; IEC 61511 covers functional safety (SIL), not cybersecurity.
Question 4: A 'Defense-in-Depth' strategy in ICS security means:
- Deploying a single, highly advanced firewall at the IT/OT boundary
- Applying multiple overlapping layers of security controls so that if one layer fails, others still protect critical assets (Correct answer)
- Encrypting all historian data at rest using AES-256 as the sole security measure
- Physically air-gapping all OT networks from any IT or internet connectivity
Correct answer: Applying multiple overlapping layers of security controls so that if one layer fails, others still protect critical assets
Defense-in-Depth applies multiple independent security layers — physical access controls, network segmentation, application whitelisting, anomaly detection, patch management, and incident response — so that no single point of failure exposes critical control systems. It is the foundational security architecture principle recommended by IEC 62443 and NIST.
Question 5: What was the primary attack vector used by the Stuxnet malware to compromise Iranian nuclear facility PLCs?
- A phishing email sent directly to plant operators
- Exploitation of zero-day Windows vulnerabilities spread via infected USB drives to reach air-gapped systems (Correct answer)
- A remote exploit over the public internet targeting SCADA web interfaces
- SQL injection attacks on the plant's historian database
Correct answer: Exploitation of zero-day Windows vulnerabilities spread via infected USB drives to reach air-gapped systems
Stuxnet spread through infected USB drives, exploiting multiple Windows zero-day vulnerabilities to bridge the air gap. Once inside, it specifically targeted Siemens S7-300 PLCs controlling centrifuge motors, subtly altering their speed while reporting normal status — the first publicly known cyberweapon targeting physical industrial infrastructure.
Question 6: What does 'network segmentation with a DMZ' accomplish in an ICS architecture?
- It eliminates the need for antivirus software on OT endpoints
- It creates an intermediate buffer zone between IT and OT networks where data exchange servers are hosted, preventing direct connections between enterprise and control networks (Correct answer)
- It allows remote vendors to directly access PLCs for maintenance without passing through any firewall
- It replaces the need for physical access controls to the control room
Correct answer: It creates an intermediate buffer zone between IT and OT networks where data exchange servers are hosted, preventing direct connections between enterprise and control networks
A DMZ (Demilitarized Zone) between IT and OT networks hosts intermediary servers (historians, data diodes, jump servers) that allow controlled data flow without establishing a direct routed path between the enterprise network and the control network. This prevents an attacker who compromises the IT network from directly reaching PLCs or SCADA systems.
What is the primary security concern that differentiates Operational Technology (OT) networks from traditional IT networks?