A critical infrastructure organization is implementing a new Industrial Control System (ICS) for its power grid. Due to the high-impact nature of potential cyberattacks, the security architect must ensure the system adheres to the 'defense-in-depth' principle. Which of the following security measures, when applied to the ICS, BEST exemplifies this principle?
- AUtilizing a demilitarized zone (DMZ) to segment the ICS network from the enterprise network, alongside network segmentation within the ICS, host-based firewalls, and application whitelisting on controllers.
- BImplementing a single, robust firewall at the perimeter of the ICS network.
- CEnforcing strong password policies and multi-factor authentication (MFA) for all ICS operator accounts.
- DDeploying an Intrusion Detection System (IDS) to monitor all traffic within the ICS network for anomalies.
Show answer & explanationAnswer & explanation
Correct answer: A. Utilizing a demilitarized zone (DMZ) to segment the ICS network from the enterprise network, alongside network segmentation within the ICS, host-based firewalls, and application whitelisting on controllers.
Defense-in-depth involves multiple layers of security controls to protect critical assets. Option B describes a multi-layered approach including network segmentation (DMZ, internal segmentation), host-based controls (firewalls), and application-level controls (whitelisting), which is a strong embodiment of this principle for ICS.
Why the other options are wrong
- B. A single firewall is a single point of failure and does not represent multiple layers of defense.
- C. Strong authentication is a critical security control, but it's a single layer focused on access, not a comprehensive defense-in-depth strategy for the entire system.
- D. An IDS is an important monitoring tool, but it's one layer of defense and primarily reactive, not a comprehensive multi-layered prevention strategy.
Defense-in-Depth
A security strategy that employs multiple layers of security controls to protect assets, so if one control fails, others are still in place.
- Layered security approach.
- Reduces reliance on a single security control.
- Applies to physical, technical, and administrative controls.
Memory trick: Layers of defense, like an onion, protect the core.