A security architect is designing an endpoint security solution for a critical industrial control system (ICS) network. The ICS endpoints are legacy systems that cannot run modern security agents or be frequently patched. The primary goal is to prevent unauthorized network access and lateral movement, treating every connection attempt as suspicious. Which secure network access design principle should be prioritized to segment and protect these vulnerable ICS endpoints?
- AFlat network design with robust antivirus.
- BRegular vulnerability scanning and penetration testing.
- CZero Trust segmentation and micro-segmentation.
- DPerimeter-based security with a strong firewall.
Show answer & explanationAnswer & explanation
Correct answer: C. Zero Trust segmentation and micro-segmentation.
Zero Trust segmentation and micro-segmentation are crucial for protecting vulnerable legacy ICS endpoints. By applying the 'never trust, always verify' principle, every connection is authenticated and authorized, and micro-segmentation strictly limits communication paths, preventing lateral movement even if a device is compromised. Perimeter firewalls are insufficient for internal lateral movement, flat networks are insecure, and scanning/testing are reactive.
Why the other options are wrong
- A. A flat network design with robust antivirus is highly insecure for critical, unpatchable legacy systems, as it allows free lateral movement and antivirus may not even run on legacy OS.
- B. Regular vulnerability scanning and penetration testing are important security practices but do not provide continuous, proactive protection against unauthorized access and lateral movement for vulnerable legacy systems.
- D. Perimeter-based security with a strong firewall protects the boundary but is ineffective at preventing lateral movement within the network if an internal device is compromised, which is critical for vulnerable ICS.
Zero Trust for Legacy ICS
Applying Zero Trust principles, particularly micro-segmentation, is critical for securing vulnerable legacy Industrial Control System (ICS) endpoints by strictly limiting communication and preventing lateral movement, as these systems cannot typically run modern agents or be patched.
- Essential for unpatchable, vulnerable systems.
- Prevents lateral movement.
- Requires strict network segmentation and policy enforcement.
Memory trick: Don't trust any connection to the old factory machines; build tiny, locked rooms for each.