CAS-002 · Question #205
Company XYZ recently acquired a manufacturing plant from Company ABC which uses a different manufacturing ICS platform. Company XYZ has strict ICS security regulations while Company ABC does not…
The correct answer is C. Conduct a risk assessment of the acquired plant ICS platform and implement any necessary. When integrating an acquired ICS environment with a different security posture, a risk assessment must come first to identify gaps and prioritize controls proportionally before any changes are made.
Question
Company XYZ recently acquired a manufacturing plant from Company ABC which uses a different manufacturing ICS platform. Company XYZ has strict ICS security regulations while Company ABC does not. Which of the following approaches would the network security administrator for Company XYZ MOST likely proceed with to integrate the new manufacturing plant?
Options
- AConduct a network vulnerability assessment of acquired plant ICS platform and correct all
- BConvert the acquired plant ICS platform to the Company XYZ standard ICS platform solely
- CConduct a risk assessment of the acquired plant ICS platform and implement any necessary
- DRequire Company ABC to bring their ICS platform into regulatory compliance prior to
How the community answered
(21 responses)- A5% (1)
- B19% (4)
- C71% (15)
- D5% (1)
Why each option
When integrating an acquired ICS environment with a different security posture, a risk assessment must come first to identify gaps and prioritize controls proportionally before any changes are made.
A vulnerability assessment is narrower than a risk assessment and identifies technical weaknesses without evaluating business impact, threat likelihood, or existing compensating controls already protecting the ICS environment.
Converting the ICS platform for standardization purposes alone, without first assessing risk, could cause unnecessary operational disruption and may not address the most critical security deficiencies.
A risk assessment allows Company XYZ to understand the specific threats, vulnerabilities, and business impacts associated with the acquired ICS platform before committing to any remediation path. This approach ensures that security controls are implemented based on actual risk exposure rather than assumptions, and it aligns with NIST SP 800-82 guidance for industrial control system security. Prioritizing controls based on risk findings also prevents over-engineering low-risk areas while ensuring critical gaps are addressed promptly.
Requiring the acquired company to achieve compliance before acquisition is not actionable post-merger; Company XYZ has assumed responsibility for the environment and must manage remediation itself.
Concept tested: ICS risk assessment prior to post-acquisition integration
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r3.pdf
Topics
Community Discussion
No community discussion yet for this question.