CAS-003 · Question #627
A manufacturing company's security engineer is concerned a remote actor may be able to access the ICS that is used to monitor the factory lines. The security engineer recently proposed some…
The correct answer is D. Running frequent vulnerability scans during the project. Demonstrating progressive attack surface reduction across multiple ICS implementation phases requires continuous, quantifiable measurement rather than point-in-time assessments.
Question
A manufacturing company's security engineer is concerned a remote actor may be able to access the ICS that is used to monitor the factory lines. The security engineer recently proposed some techniques to reduce the attack surface of the ICS to the Chief Information Security Officer (CISO). Which of the following would BEST track the reductions to show the CISO the engineer's plan is successful during each phase?
Options
- AConducting tabletop exercises to evaluate system risk
- BContracting a third-party auditor after the project is finished
- CPerforming pre- and post-implementation penetration tests
- DRunning frequent vulnerability scans during the project
How the community answered
(20 responses)- A5% (1)
- B5% (1)
- C20% (4)
- D70% (14)
Why each option
Demonstrating progressive attack surface reduction across multiple ICS implementation phases requires continuous, quantifiable measurement rather than point-in-time assessments.
Tabletop exercises evaluate hypothetical incident response scenarios and risk reasoning but do not produce quantifiable attack surface metrics to track phase-by-phase reductions.
A third-party audit scheduled only after project completion cannot provide visibility into incremental progress during each intermediate implementation phase.
Pre- and post-implementation penetration tests capture only two data points in time and cannot show the incremental, per-phase improvements the CISO requires.
Running frequent vulnerability scans throughout the project generates ongoing, measurable data showing the number and severity of identified vulnerabilities decreasing at each implementation phase. This continuous baseline allows the security engineer to present the CISO with clear, phase-by-phase evidence that each defensive change is having the intended effect. Vulnerability scanning directly quantifies attack surface components such as open ports, unpatched services, and weak configurations on the ICS.
Concept tested: ICS attack surface reduction measurement and tracking
Source: https://csrc.nist.gov/pubs/sp/800/82/r3/final
Topics
Community Discussion
No community discussion yet for this question.