โ† All ICS Flashcard Decks

Communication & Conflict Resolution Flashcards

7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Communication & Conflict Resolution flashcards as text
  1. What is the PRIMARY purpose of a communications plan in an ICS incident response plan (IRP)?

    Answer: To define who communicates what information to whom and when during an incident

    A communications plan ensures structured, timely, and accurate information flow among all stakeholders during an ICS incident.

  2. A field technician and an ICS cybersecurity analyst disagree about whether a legacy RTU should be replaced or patched. Which conflict resolution approach is MOST constructive?

    Answer: Conduct a formal risk assessment comparing residual risk of patching vs. replacement cost and timeline

    A formal risk assessment provides objective data to guide decisions involving technical and financial trade-offs.

  3. In ICS environments, 'purdue model' segmentation directly supports conflict resolution between IT and OT by:

    Answer: Clearly defining the boundary between IT and OT responsibilities through hierarchical network zones

    The Purdue Reference Model establishes clear network zones that define where IT security controls end and OT operational controls begin.

  4. When drafting security policies for ICS environments, why is it important to include OT engineers in the writing process?

    Answer: OT engineers understand operational constraints that could make IT-centric policies unworkable or unsafe

    OT engineers provide critical operational context that prevents policies from inadvertently disrupting safety-critical processes.

  5. Which of the following is an example of 'constructive conflict' in an ICS security program?

    Answer: A red team challenging assumptions in an ICS defense architecture to identify weaknesses

    Constructive conflict, like red team exercises, challenges existing assumptions to improve security outcomes rather than creating dysfunction.

  6. An ICS site receives a threatening anonymous tip about a planned cyberattack. Who should be notified FIRST according to standard incident communication protocols?

    Answer: The internal security incident response team and site management simultaneously

    Internal security and management must be notified immediately so the organization can assess credibility and activate its response plan.

  7. In ICS security, the term 'zone of responsibility' in communications primarily refers to:

    Answer: The defined scope of authority each team has to make decisions and communicate about specific system areas

    Clearly defined zones of responsibility prevent communication gaps and authority conflicts by specifying who owns each decision domain.