nerdexam
CompTIA

CAS-002 · Question #205

Company XYZ recently acquired a manufacturing plant from Company ABC which uses a different manufacturing ICS platform. Company XYZ has strict ICS security regulations while Company ABC does not…

The correct answer is C. Conduct a risk assessment of the acquired plant ICS platform and implement any necessary. When integrating an acquired ICS environment with a different security posture, a risk assessment must come first to identify gaps and prioritize controls proportionally before any changes are made.

Integration of Computing, Communications and Business Disciplines

Question

Company XYZ recently acquired a manufacturing plant from Company ABC which uses a different manufacturing ICS platform. Company XYZ has strict ICS security regulations while Company ABC does not. Which of the following approaches would the network security administrator for Company XYZ MOST likely proceed with to integrate the new manufacturing plant?

Options

  • AConduct a network vulnerability assessment of acquired plant ICS platform and correct all
  • BConvert the acquired plant ICS platform to the Company XYZ standard ICS platform solely
  • CConduct a risk assessment of the acquired plant ICS platform and implement any necessary
  • DRequire Company ABC to bring their ICS platform into regulatory compliance prior to

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    19% (4)
  • C
    71% (15)
  • D
    5% (1)

Why each option

When integrating an acquired ICS environment with a different security posture, a risk assessment must come first to identify gaps and prioritize controls proportionally before any changes are made.

AConduct a network vulnerability assessment of acquired plant ICS platform and correct all

A vulnerability assessment is narrower than a risk assessment and identifies technical weaknesses without evaluating business impact, threat likelihood, or existing compensating controls already protecting the ICS environment.

BConvert the acquired plant ICS platform to the Company XYZ standard ICS platform solely

Converting the ICS platform for standardization purposes alone, without first assessing risk, could cause unnecessary operational disruption and may not address the most critical security deficiencies.

CConduct a risk assessment of the acquired plant ICS platform and implement any necessaryCorrect

A risk assessment allows Company XYZ to understand the specific threats, vulnerabilities, and business impacts associated with the acquired ICS platform before committing to any remediation path. This approach ensures that security controls are implemented based on actual risk exposure rather than assumptions, and it aligns with NIST SP 800-82 guidance for industrial control system security. Prioritizing controls based on risk findings also prevents over-engineering low-risk areas while ensuring critical gaps are addressed promptly.

DRequire Company ABC to bring their ICS platform into regulatory compliance prior to

Requiring the acquired company to achieve compliance before acquisition is not actionable post-merger; Company XYZ has assumed responsibility for the environment and must manage remediation itself.

Concept tested: ICS risk assessment prior to post-acquisition integration

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r3.pdf

Topics

#ICS security#risk assessment#acquisition integration#regulatory compliance

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice