Certified Information Security Manager (CISM)Information Security Risk ManagementMedium

A manufacturing company is implementing a new Supervisory Control and Data Acquisition (SCADA) system for its critical production line. The Chief Information Security Officer (CISO) is concerned about potential cyber-physical risks. Which of the following risk management strategies is MOST appropriate for mitigating the unique threats associated with operational technology (OT) systems like SCADA?

  1. AIsolating the SCADA network from the corporate IT network and implementing strict physical access controls.
  2. BDeploying advanced endpoint detection and response (EDR) solutions on all SCADA controllers.
  3. CImplementing a comprehensive security awareness training program for all corporate employees.
  4. DRelying solely on traditional IT firewalls and intrusion detection systems (IDS) for network protection.
Show answer & explanation

Correct answer: A. Isolating the SCADA network from the corporate IT network and implementing strict physical access controls.

Isolating OT networks (like SCADA) from IT networks (network segmentation/air gapping) is a fundamental and highly effective strategy to prevent IT-borne threats from impacting critical control systems. Combined with physical access controls, it directly addresses cyber-physical risks.

Why the other options are wrong

  • B. While EDR is valuable, many legacy OT systems may not support it, and isolation is a more fundamental first step for OT security.
  • C. Security awareness is important, but it's a general security measure and not the most specific or effective strategy for direct OT cyber-physical risk mitigation.
  • D. Traditional IT firewalls and IDS may not be adequate for the unique protocols and real-time requirements of OT, and they don't address physical risks.

OT Security Strategy

Specific security controls and practices designed to protect operational technology (OT) systems, which control physical processes, from cyber and physical threats.

  • Prioritizes safety and availability over confidentiality.
  • Often involves network segmentation and physical controls.
  • Addresses unique protocols and legacy systems.

Memory trick: OT Security: Segment and Protect the Physical.

More Information Security Risk Management questions