nerdexam
CompTIA

CAS-003 · Question #539

A company relies on an ICS to perform equipment monitoring functions that are federally mandated for operation of the facility. Fines for non-compliance could be costly. The ICS has known…

The correct answer is B. Transfer the risk associated with the ICS vulnerabilities. When an ICS cannot be patched, cannot be removed due to regulatory mandates, and cyber-liability insurance is unavailable, risk transfer through alternative contractual or operational mechanisms is the best available risk management strategy.

Risk Management

Question

A company relies on an ICS to perform equipment monitoring functions that are federally mandated for operation of the facility. Fines for non-compliance could be costly. The ICS has known vulnerabilities and can no longer be patched or updated. Cyber-liability insurance cannot be obtained because insurance companies will not insure this equipment. Which of the following would be the BEST option to manage this risk to the company's production environment?

Options

  • AAvoid the risk by removing the ICS from production
  • BTransfer the risk associated with the ICS vulnerabilities
  • CMitigate the risk by restricting access to the ICS
  • DAccept the risk and upgrade the ICS when possible

How the community answered

(50 responses)
  • A
    8% (4)
  • B
    64% (32)
  • C
    22% (11)
  • D
    6% (3)

Why each option

When an ICS cannot be patched, cannot be removed due to regulatory mandates, and cyber-liability insurance is unavailable, risk transfer through alternative contractual or operational mechanisms is the best available risk management strategy.

AAvoid the risk by removing the ICS from production

The ICS is federally mandated for facility operation, so removing it from production would create a direct compliance violation and trigger the costly fines the company is trying to avoid.

BTransfer the risk associated with the ICS vulnerabilitiesCorrect

Risk transfer is not limited to insurance - it can also be achieved through contractual indemnification agreements with vendors, outsourcing ICS operations to a third-party managed service provider who assumes liability, or service-level agreements that shift financial responsibility for incidents to an external party. This approach is preferred over acceptance because it actively redistributes the financial and operational impact of a breach rather than leaving the company fully exposed to the known vulnerabilities and associated fine risk.

CMitigate the risk by restricting access to the ICS

Restricting access to the ICS reduces the attack surface but does not remediate the known, unpatched vulnerabilities - a sufficiently motivated attacker or malicious insider could still exploit them.

DAccept the risk and upgrade the ICS when possible

Accepting the risk without a firm upgrade commitment leaves the company fully exposed to known exploitable vulnerabilities indefinitely, which is the least protective posture when alternative risk management options are still available.

Concept tested: ICS risk management strategies when patching is unavailable

Source: https://csrc.nist.gov/publications/detail/sp/800-82/rev-3/final

Topics

#ICS security#legacy systems#risk transfer#risk management

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice