CAS-003 · Question #671
An organization is integrating an ICS and wants to ensure the system is cyber resilient. Unfortunately, many of the specialized components are legacy systems that cannot be patched. The existing…
The correct answer is A. Vulnerable components. When integrating legacy ICS components that cannot be patched, the foundational design assumption that MUST be made is that those components are and will remain vulnerable. Accepting this as a given constraint allows the security architect to design compensating controls around…
Question
An organization is integrating an ICS and wants to ensure the system is cyber resilient. Unfortunately, many of the specialized components are legacy systems that cannot be patched. The existing enterprise consists of mission-critical systems that require 99.9% uptime. To assist in the appropriate design of the system given the constraints, which of the following MUST be assumed?
Options
- AVulnerable components
- BOperational impact due to attack
- CTime criticality of systems
- DPresence of open-source software
How the community answered
(50 responses)- A82% (41)
- B4% (2)
- C4% (2)
- D10% (5)
Explanation
When integrating legacy ICS components that cannot be patched, the foundational design assumption that MUST be made is that those components are and will remain vulnerable. Accepting this as a given constraint allows the security architect to design compensating controls around those components - such as network segmentation, unidirectional gateways, application whitelisting, and anomaly detection - rather than relying on patching. Operational impact due to attack (B) and time criticality (C) are important considerations but are consequences of the vulnerability, not the root assumption driving the design. The presence of open-source software (D) is not inherently relevant to legacy ICS resilience design.
Topics
Community Discussion
No community discussion yet for this question.