CAS-002 · Question #360
The risk manager is reviewing a report which identifies a requirement to keep a business critical legacy system operational for the next two years. The legacy system is out of support because the…
The correct answer is B. Segment the device on its own secure network. A legacy out-of-support embedded system with unknown internals requires compensating controls; network segmentation is the most practical and effective risk reduction measure available.
Question
The risk manager is reviewing a report which identifies a requirement to keep a business critical legacy system operational for the next two years. The legacy system is out of support because the vendor and security patches are no longer released. Additionally, this is a proprietary embedded system and little is documented and known about it. Which of the following should the Information Technology department implement to reduce the security risk from a compromise of this system?
Options
- AVirtualize the system and migrate it to a cloud provider.
- BSegment the device on its own secure network.
- CInstall an antivirus and HIDS on the system.
- DHire developers to reduce vulnerabilities in the code.
How the community answered
(40 responses)- A5% (2)
- B73% (29)
- C15% (6)
- D8% (3)
Why each option
A legacy out-of-support embedded system with unknown internals requires compensating controls; network segmentation is the most practical and effective risk reduction measure available.
A proprietary embedded system cannot be virtualized and migrated to a cloud provider because its architecture is hardware-dependent and its internals are undocumented.
Segmenting the device on its own isolated network limits the blast radius of any compromise by preventing lateral movement to other systems. Since the system cannot be patched and its code is largely unknown, network isolation acts as a compensating control that contains threats without requiring changes to the system itself. This is a standard recommendation for legacy and end-of-life systems that must remain operational.
Installing antivirus and HIDS may not be feasible on a proprietary embedded system, and even if possible, these tools cannot patch the underlying unaddressed vulnerabilities.
Hiring developers to reduce vulnerabilities is impractical because the system is proprietary with little documentation, making code analysis and remediation extremely time-consuming and risky within the two-year window.
Concept tested: Network segmentation as compensating control for legacy systems
Source: https://csrc.nist.gov/publications/detail/sp/800-82/rev-3/final
Topics
Community Discussion
No community discussion yet for this question.