nerdexam
Isaca

CISA · Question #201

Which of the following findings from an industrial control system (ICS) audit should an IS auditor recommend be addresses FIRST?

The correct answer is C. Incomplete isolation of the ICS network. Incomplete isolation of the ICS network (C) is the highest priority because a network boundary failure exposes safety-critical operational technology (OT) directly to IT networks or the internet, enabling attackers to cause physical damage, production outages, or even loss of lif

Submitted by suresh_in· Apr 18, 2026Protection of Information Assets

Question

Which of the following findings from an industrial control system (ICS) audit should an IS auditor recommend be addresses FIRST?

Options

  • AInconsistent physical security for the ICS devices
  • BTechnical obsolescence of ICS devices
  • CIncomplete isolation of the ICS network
  • DLack of security standards for the ICS

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    6% (1)
  • C
    76% (13)
  • D
    12% (2)

Explanation

Incomplete isolation of the ICS network (C) is the highest priority because a network boundary failure exposes safety-critical operational technology (OT) directly to IT networks or the internet, enabling attackers to cause physical damage, production outages, or even loss of life - an immediate, high-impact risk that no compensating control can fully offset.

Why the distractors fall short:

  • A (Physical security) is serious but localized - an attacker needs physical presence, limiting blast radius compared to a network-accessible system.
  • B (Technical obsolescence) is a long-term risk; aging devices may still be adequately protected if properly isolated and monitored.
  • D (Lack of standards) is a governance gap that matters, but it's a root cause of future vulnerabilities - not an active exposure today.

Memory tip: Think of ICS risk in layers - network isolation is the outer wall. If that wall has a hole, everything inside is exposed regardless of how well you manage the other layers. In ISACA's risk prioritization logic, active exposure beats governance gaps, and network-level threats beat physical-level threats due to scale and remote exploitability.

Topics

#ICS Security#Network Segmentation#Vulnerability Prioritization#Risk Management

Community Discussion

No community discussion yet for this question.

Full CISA Practice