ICS Security Standards and Compliance Frameworks 2 — Questions and Answers
Question 1: Which NERC CIP standard specifically addresses Electronic Security Perimeters (ESPs) for bulk electric system cyber assets?
- NERC CIP-005 (Correct answer)
- NERC CIP-007
- NERC CIP-010
- NERC CIP-013
Correct answer: NERC CIP-005
NERC CIP-005 defines requirements for identifying and protecting Electronic Security Perimeters around high and medium impact BES cyber systems.
Question 2: The IEC 62443 standard series addresses security for which type of systems?
- Enterprise IT networks
- Industrial Automation and Control Systems (IACS) (Correct answer)
- Cloud computing platforms
- Mobile device management
Correct answer: Industrial Automation and Control Systems (IACS)
IEC 62443 is the international standard series specifically developed for Industrial Automation and Control Systems (IACS) security.
Question 3: Under NIST SP 800-82, which security zone concept involves grouping OT assets with similar security requirements?
- Defense-in-depth layers
- Security zones and conduits (Correct answer)
- Trust levels and domains
- Access control rings
Correct answer: Security zones and conduits
NIST SP 800-82 adopts IEC 62443's zones and conduits concept to group OT assets by security requirements and manage inter-zone communications.
Question 4: Which compliance framework mandates that critical infrastructure owners report significant cybersecurity incidents to CISA within 72 hours?
- NERC CIP
- CIRCIA (Correct answer)
- FISMA
- HIPAA
Correct answer: CIRCIA
The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) requires covered entities to report significant cyber incidents to CISA within 72 hours.
Question 5: In IEC 62443, what term describes the maximum tolerable level of security risk for a given system or zone?
- Security Assurance Level (SAL)
- Target Security Level (SL-T) (Correct answer)
- Risk Acceptance Threshold (RAT)
- Capability Security Level (SL-C)
Correct answer: Target Security Level (SL-T)
The Target Security Level (SL-T) in IEC 62443 defines the desired security level that a zone or conduit must achieve based on risk assessment.
Question 6: Which NIST framework function focuses on developing organizational understanding to manage cybersecurity risk?
- Protect
- Identify (Correct answer)
- Detect
- Respond
Correct answer: Identify
The Identify function of the NIST Cybersecurity Framework involves understanding the organization's assets, business environment, governance, risk, and vulnerabilities.
Question 7: Which NERC CIP standard requires utilities to implement a patch management process for BES cyber systems?
- CIP-006
- CIP-007 (Correct answer)
- CIP-009
- CIP-011
Correct answer: CIP-007
NERC CIP-007 (Systems Security Management) requires utilities to implement security patch management programs for BES cyber systems.
Which NERC CIP standard specifically addresses Electronic Security Perimeters (ESPs) for bulk electric system cyber assets?