CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityMedium

A manufacturing company is implementing a new Industrial Control System (ICS) to automate its production line. The ICS will be connected to the corporate network for monitoring and reporting. To protect the operational technology (OT) environment from threats originating from the IT network, which security control is MOST critical to implement?

  1. ANetwork segmentation and a demilitarized zone (DMZ).
  2. BSecurity Information and Event Management (SIEM) system.
  3. CStrong access control policies for all users.
  4. DRegular vulnerability scanning of ICS devices.
Show answer & explanation

Correct answer: A. Network segmentation and a demilitarized zone (DMZ).

Network segmentation, often implemented with a DMZ between IT and OT networks, is crucial for isolating the sensitive OT environment. This prevents threats from the IT network from directly impacting the ICS. While other options are important, segmentation provides the fundamental boundary protection needed for converged IT/OT environments.

Why the other options are wrong

  • B. A SIEM is for monitoring and detection, but does not prevent direct attacks across network boundaries.
  • C. Strong access control is vital for internal security but does not protect the OT network from external threats originating from the IT network itself.
  • D. Vulnerability scanning helps identify weaknesses but does not provide boundary protection against IT-originated threats.

Network Segmentation (IT/OT)

Dividing a computer network into smaller, isolated sub-networks to reduce the attack surface, limit lateral movement of threats, and protect critical systems like Operational Technology (OT).

  • Crucial for converged IT/OT environments.
  • Often involves firewalls, VLANs, and DMZs.
  • Enhances security by containing breaches.

Memory trick: Separate 'IT' from 'OT' to 'Secure' the 'Factory'.

More Information Technology and Security questions