CAS-002 · Question #817
The latest independent research shows that cyber attacks involving SCADA systems grew an average of 15% per year in each of the last four years, but that this year's growth has slowed to around 7%…
The correct answer is B. Spending on SCADA security controls should stay steady; application control spending should. Security spending should be adjusted based on attack trend data - stable or declining threats warrant steady or reduced spending, while exponentially growing threats require increased investment.
Question
The latest independent research shows that cyber attacks involving SCADA systems grew an average of 15% per year in each of the last four years, but that this year's growth has slowed to around 7%. Over the same time period, the number of attacks against applications has decreased or stayed flat each year. At the start of the measure period, the incidence of PC boot loader or BIOS based attacks was negligible. Starting two years ago, the growth in the number of PC boot loader attacks has grown exponentially. Analysis of these trends would seem to suggest which of the following strategies should be employed?
Options
- ASpending on SCADA protections should stay steady; application control spending should
- BSpending on SCADA security controls should stay steady; application control spending should
- CSpending all controls should increase by 15% to start; spending on application controls should be
- DSpending on SCADA security controls should increase by 15%; application control spending
How the community answered
(29 responses)- A7% (2)
- B55% (16)
- C14% (4)
- D24% (7)
Why each option
Security spending should be adjusted based on attack trend data - stable or declining threats warrant steady or reduced spending, while exponentially growing threats require increased investment.
This option incorrectly handles the bootloader spending allocation by not prioritizing the exponentially growing bootloader and BIOS threat with a sufficient budget increase.
SCADA attack growth has slowed significantly from 15% to 7%, suggesting existing controls are effective and spending should remain steady rather than increase. Application attack counts are flat or declining, indicating current controls are sufficient and spending could potentially be reduced. The exponential growth of PC bootloader and BIOS attacks represents the most rapidly emerging threat and warrants the greatest increase in security investment.
A blanket 15% increase across all controls ignores the trend data showing SCADA growth has slowed and application attacks have not increased, misallocating the security budget.
Increasing SCADA spending by 15% contradicts the trend showing SCADA attack growth has actually slowed to 7%, which does not justify a budget increase of that magnitude.
Concept tested: Security budget allocation based on threat trend analysis
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.