CompTIA SecurityX (CAS-005)Security EngineeringMedium
A critical infrastructure organization is implementing a new Industrial Control System (ICS) for its power grid. Due to the severe consequences of a cyber-attack, the organization requires an absolute guarantee that no data can flow from the less trusted business network into the highly sensitive ICS network. Which security control is MOST effective for enforcing this unidirectional data flow?
- AFirewall with strict ACLs
- BIntrusion Prevention System (IPS)
- CData Diode
- DVirtual Private Network (VPN)
Show answer & explanationAnswer & explanation
Correct answer: C. Data Diode
A data diode (or unidirectional gateway) is a hardware device that physically enforces one-way data transfer, providing an absolute guarantee that no data can flow in the reverse direction. This is crucial for highly sensitive ICS/OT environments where inbound data flow from less trusted networks is strictly prohibited.
Why the other options are wrong
- A. Firewalls, even with strict ACLs, are software-based and can theoretically be bypassed or misconfigured, not offering an absolute guarantee.
- B. An IPS detects and blocks malicious activity but relies on software and signatures, and it doesn't physically prevent bidirectional flow.
- D. A VPN establishes a secure tunnel but still allows bidirectional communication within that tunnel, making it unsuitable for strictly unidirectional requirements.
Data Diode (Unidirectional Gateway)
A hardware device that permits data flow in only one direction, physically preventing any return path or reverse communication.
- Physically enforces one-way data transfer
- Used in high-security environments (e.g., ICS/OT)
- Eliminates the possibility of cyber-attacks originating from the less trusted network
Memory trick: A data diode is like a one-way street for data, no U-turns allowed.