CAS-003 · Question #716
A manufacturing company employs SCADA systems to drive assembly lines across geographically dispersed sites. Therefore, the company must use the Internet to transport control messages and responses…
The correct answer is A. Design a patch management capability for control systems. E. Isolate control systems from enterprise systems. Patch management reduces exploitable vulnerabilities in SCADA software, and network isolation creates a security boundary that limits lateral movement from enterprise systems into the OT environment.
Question
A manufacturing company employs SCADA systems to drive assembly lines across geographically dispersed sites. Therefore, the company must use the Internet to transport control messages and responses. Which of the following architectural changes when integrated will BEST reduce the manufacturing control system's attack surface? (Select TWO)
Options
- ADesign a patch management capability for control systems.
- BImplement supply chain security.
- CIntegrate message authentication
- DAdd sensors and collectors at the Internet boundary.
- EIsolate control systems from enterprise systems.
- FImplement a site-to-site VPN across sites
How the community answered
(24 responses)- A67% (16)
- B8% (2)
- D4% (1)
- F21% (5)
Why each option
Patch management reduces exploitable vulnerabilities in SCADA software, and network isolation creates a security boundary that limits lateral movement from enterprise systems into the OT environment.
A formalized patch management capability ensures SCADA firmware and software receive timely security updates, reducing the number of known CVEs that an Internet-based attacker can exploit against exposed control system endpoints.
Supply chain security addresses the integrity of hardware and software during procurement and distribution, but it does not reduce the runtime network attack surface of already-deployed SCADA systems that are currently exposed to Internet traffic.
Message authentication verifies the integrity and origin of individual control messages in transit, but it is a compensating control rather than an architectural change that reduces the overall number of systems or network vectors exposed to attack.
Adding sensors and collectors at the Internet boundary increases visibility and detection capability but does not remove or restrict any attack vector - the attack surface itself remains unchanged by this monitoring addition.
Isolating control systems from enterprise IT networks establishes a dedicated OT security zone with strict ingress and egress controls, preventing an enterprise compromise from propagating laterally into the manufacturing control environment and significantly shrinking the reachable attack surface.
A site-to-site VPN encrypts the Internet transport channel but all SCADA endpoints remain reachable through the established tunnel, so a compromise of any VPN-connected site still provides access paths into the control systems.
Concept tested: ICS/SCADA attack surface reduction through isolation and patch management
Source: https://www.cisa.gov/topics/industrial-control-systems
Topics
Community Discussion
No community discussion yet for this question.