QUESTIONS WITH 100% CORRECT
ANSWERS GRADED A+
⩥ What happens during the Develop & Implement phase of ICS security
implementation? Answer: Countermeasures are implemented to meet the
Target Security Level (SL-T).
⩥ What is the primary goal of the Maintain phase in ICS security
implementation? Answer: To ensure the Achieved Security Level (SL-A)
is equal to or better than the Target Security Level (SL-T).*
⩥ What is phase 1 of the IACS Cybersecurity Life Cycle? Answer:
Assess
⩥ What is phase 2 of the IACS Cybersecurity Life Cycle? Answer:
Develop & Implement
⩥ What is phase 3 of the IACS Cybersecurity Life Cycle? Answer:
Maintain phase
⩥ What is step 1 of the IACS Cybersecurity Life Cycle (Assess Phase)?
Answer: High-Level Cyber Risk Assessment
,⩥ What is step 2 of the IACS Cybersecurity Life Cycle (Assess Phase)?
Answer: Allocation of IACS Assets to Security Zones or Conduits
⩥ What is step 3 of the IACS Cybersecurity Life Cycle (Assess Phase)?
Answer: Detail Cyber Risk Assessment
⩥ What is step 4 of the IACS Cybersecurity Life Cycle (Develop &
Implement Phase)? Answer: Cybersecurity Requirements Specification
⩥ What is step 5 of the IACS Cybersecurity Life Cycle (Develop &
Implement Phase)? Answer: Design and engineering of Cybersecurity
countermeasures
⩥ What is step 6 of the IACS Cybersecurity Life Cycle (Develop &
Implement Phase)? Answer: Installation, commissioning and validation
of Cybersecurity countermeasures
⩥ What is step 7 of the IACS Cybersecurity Life Cycle (Maintain)?
Answer: Cybersecurity Maintenance, Monitoring and Management of
Change
⩥ What is step 8 of the IACS Cybersecurity Life Cycle (Maintain)?
Answer: Cyber Incident Response & Recovery
,⩥ What are the continuous processes activities of the IACS
Cybersecurity Life Cycle? Answer: Cybersecurity Management System:
Policies, Procedures, Training & Awareness, Periodic Cybersecurity
Audits
⩥ A risk assessment should provide information about what? Answer:
An entire system as well as each zone
⩥ What information should be provided from a risk assessment?
Answer: -Risk profile
-Highest severity consequences
-Threats / vulnerabilities leading to the highest risks
-Target Security Levels
-Recommendations
⩥ A thorough risk assessment should deliver insights on system-wide,
zone-specific, and conduit-specific levels and generate: Answer: -Risk
profile
-Highest severity consequences
-Threats / vulnerabilities leading to the highest risks
-Target Security Levels
-Recommendations
, ⩥ What is the output of a Risk Assessment called? Answer:
Cybersecurity Requirement Specification (CRS)
⩥ The CRS must include at least the following: Answer: SUC
description
Zone and conduit drawings
Zone and conduit characteristics
Operating environment assumptions
Threat environment
Organizational security policies
Tolerable risk
Regulatory requirements
⩥ What documents are required per zone/conduit? Answer: •Name
and/or unique identifier
•Accountable organization(s)
•Definition of logical boundary
•Definition of physical boundary, if applicable
•Safety designation
•List of all logical access points
•List of all physical access points
•List of data flows associated with each access point
•Connected zones or conduits