A security administrator is evaluating content security solutions for an industrial control system (ICS) network. The ICS network has stringent requirements for low latency and deterministic behavior. Internet access from the ICS network is highly restricted, but necessary for critical updates from specific vendor sites. Which content security strategy is most appropriate for this environment, prioritizing security without compromising operational integrity?
- AUtilizing a Cloud Access Security Broker (CASB) to protect all cloud-based ICS applications.
- BInstalling endpoint detection and response (EDR) agents on all ICS devices for real-time monitoring.
- CImplementing a DNS-layer security solution with specific whitelisting for approved vendor update domains.
- DDeploying a full-proxy Secure Web Gateway (SWG) with deep packet inspection for all outbound traffic.
Show answer & explanationAnswer & explanation
Correct answer: C. Implementing a DNS-layer security solution with specific whitelisting for approved vendor update domains.
For ICS networks, low latency and deterministic behavior are critical. A DNS-layer security solution (like Cisco Umbrella) offers protection by blocking malicious domains at the DNS resolution stage, which is very low-latency and doesn't interfere with the data plane. Whitelisting specific vendor domains ensures necessary updates can occur without introducing the overhead of deep packet inspection, which could disrupt ICS operations.
Why the other options are wrong
- A. CASBs are for cloud application security; ICS networks typically have on-premise, specialized systems, and the requirement is for internet access control, not cloud app protection.
- B. Installing EDR agents on ICS devices can introduce compatibility issues, performance overhead, and potential instability to sensitive, often proprietary, control systems.
- D. Full-proxy SWGs with deep packet inspection introduce significant latency and processing overhead, which is unacceptable for ICS networks.
ICS Content Security Strategy
Content security for Industrial Control Systems (ICS) prioritizes operational integrity and low latency, often relying on non-intrusive methods like DNS-layer security with strict whitelisting for external communications.
- ICS networks require high availability and deterministic operations.
- Deep packet inspection or endpoint agents can disrupt ICS systems.
- DNS-layer security offers low-latency, non-intrusive protection.
- Strict whitelisting is common for external access in ICS.
Memory trick: Industrial Control Systems: Low Latency, DNS Layer, Whitelist Wins.