Security Standards and Compliance Frameworks Flashcards
7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security Standards and Compliance Frameworks flashcards as text
Which aspect of ICS security does NIST SP 800-82 identify as the most significant difference from traditional IT security?
Answer: Prioritization of availability and safety over confidentiality
NIST SP 800-82 highlights that ICS environments prioritize system availability and safety (due to physical process impacts) over confidentiality, which is the reverse of traditional IT priorities.
Under NERC CIP-006, what type of access must be logged and monitored for Physical Security Perimeters (PSPs)?
Answer: Physical entry and exit of personnel and devices
NERC CIP-006 requires utilities to log and retain records of all physical entry and exit through Physical Security Perimeter access points, including the identity of individuals.
Which ISA/IEC 62443 component level standard (part 4-2) defines technical security requirements for what types of components?
Answer: Host devices, network devices, software applications, and embedded devices
IEC 62443-4-2 specifies technical security requirements for individual IACS components: host devices, network devices, software applications, and embedded devices.
In a NERC CIP compliance audit, which document type provides the primary evidence that a utility has satisfied a given requirement?
Answer: Compliance evidence packages including logs, configurations, and records
NERC CIP audits require utilities to produce evidence packages containing logs, configuration screenshots, training records, and other artifacts demonstrating ongoing compliance.
What does the concept of 'conduit' mean in the IEC 62443 zone and conduit model?
Answer: A defined path for data flows between security zones
In IEC 62443, a conduit is a defined communication pathway between two or more zones, with its own security requirements governing what traffic can traverse the zone boundaries.
Which NIST document provides a risk management framework (RMF) process applicable to federal ICS and OT systems?
Answer: NIST SP 800-37
NIST SP 800-37 defines the Risk Management Framework (RMF) — a six-step process (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor) applied to federal information systems including OT.
Under NERC CIP-008, what is the minimum required outcome of an incident response plan for a BES cyber security incident?
Answer: Roles and responsibilities, response actions, and post-incident review
NERC CIP-008 requires incident response plans to document roles, responsibilities, specific response actions, and a post-incident review process for BES cyber security incidents.