CAS-003 · Question #539
A company relies on an ICS to perform equipment monitoring functions that are federally mandated for operation of the facility. Fines for non-compliance could be costly. The ICS has known…
The correct answer is B. Transfer the risk associated with the ICS vulnerabilities. When an ICS cannot be patched, cannot be removed due to regulatory mandates, and cyber-liability insurance is unavailable, risk transfer through alternative contractual or operational mechanisms is the best available risk management strategy.
Question
A company relies on an ICS to perform equipment monitoring functions that are federally mandated for operation of the facility. Fines for non-compliance could be costly. The ICS has known vulnerabilities and can no longer be patched or updated. Cyber-liability insurance cannot be obtained because insurance companies will not insure this equipment. Which of the following would be the BEST option to manage this risk to the company's production environment?
Options
- AAvoid the risk by removing the ICS from production
- BTransfer the risk associated with the ICS vulnerabilities
- CMitigate the risk by restricting access to the ICS
- DAccept the risk and upgrade the ICS when possible
How the community answered
(50 responses)- A8% (4)
- B64% (32)
- C22% (11)
- D6% (3)
Why each option
When an ICS cannot be patched, cannot be removed due to regulatory mandates, and cyber-liability insurance is unavailable, risk transfer through alternative contractual or operational mechanisms is the best available risk management strategy.
The ICS is federally mandated for facility operation, so removing it from production would create a direct compliance violation and trigger the costly fines the company is trying to avoid.
Risk transfer is not limited to insurance - it can also be achieved through contractual indemnification agreements with vendors, outsourcing ICS operations to a third-party managed service provider who assumes liability, or service-level agreements that shift financial responsibility for incidents to an external party. This approach is preferred over acceptance because it actively redistributes the financial and operational impact of a breach rather than leaving the company fully exposed to the known vulnerabilities and associated fine risk.
Restricting access to the ICS reduces the attack surface but does not remediate the known, unpatched vulnerabilities - a sufficiently motivated attacker or malicious insider could still exploit them.
Accepting the risk without a firm upgrade commitment leaves the company fully exposed to known exploitable vulnerabilities indefinitely, which is the least protective posture when alternative risk management options are still available.
Concept tested: ICS risk management strategies when patching is unavailable
Source: https://csrc.nist.gov/publications/detail/sp/800-82/rev-3/final
Topics
Community Discussion
No community discussion yet for this question.