A manufacturing company is integrating its operational technology (OT) network with its information technology (IT) network to gain efficiencies through data analytics. The CISO is concerned about the increased risk to critical production systems. Which of the following risk management strategies is MOST appropriate to address the unique challenges of OT security in this converged environment?
- APrioritize patching and software updates on OT systems to match IT schedules.
- BApply standard IT security controls and frameworks directly to the OT environment.
- CImplement a robust intrusion detection system (IDS) on the IT network segment.
- DEstablish a demilitarized zone (DMZ) with strict one-way data flow for OT data to the IT network.
Show answer & explanationAnswer & explanation
Correct answer: D. Establish a demilitarized zone (DMZ) with strict one-way data flow for OT data to the IT network.
Establishing a DMZ with strict one-way data flow (data diode or similar) from OT to IT is a common and highly effective strategy for converged IT/OT environments. It allows OT data to be leveraged in IT while maintaining strong segmentation and preventing threats from crossing back into the sensitive OT network, which often has different priorities (availability, safety) than IT.
Why the other options are wrong
- A. Prioritizing patching on OT systems to match IT schedules is often impractical due to system stability, uptime requirements, and vendor constraints, and can introduce more risk than it mitigates in OT.
- B. Standard IT controls often conflict with OT priorities (e.g., availability, real-time operations, legacy systems) and can cause instability, making direct application inappropriate.
- C. An IDS on the IT network segment is a valuable control but does not address the fundamental architectural challenge of isolating OT from IT threats in a converged environment.
IT/OT Convergence Security
The process of integrating information technology (IT) systems with operational technology (OT) systems, requiring specialized security strategies to manage distinct risk profiles, priorities, and capabilities.
- OT prioritizes safety and availability over confidentiality.
- Legacy OT systems are often unpatchable.
- Segmentation (e.g., DMZ, data diodes) is critical for risk reduction.
Memory trick: OT needs One-way Traffic to IT.