A CISA is auditing the endpoint security controls of a manufacturing company. The company uses industrial control systems (ICS) and operational technology (OT) in its production environment, which are isolated from the corporate IT network. The CISA observes that antivirus software on these OT endpoints is rarely updated, and intrusion detection systems (IDS) are not deployed within the OT network. However, the OT network has strict physical access controls and is air-gapped from the internet. What is the MOST significant residual risk the CISA should highlight?
- ALack of real-time threat intelligence updates for the OT environment due to air-gapping.
- BA sophisticated, targeted attack could still compromise OT systems via removable media or supply chain.
- CNon-compliance with industry-specific regulations requiring continuous monitoring of OT systems.
- DThe corporate IT network is vulnerable to malware propagation if an endpoint is compromised.
Show answer & explanationAnswer & explanation
Correct answer: B. A sophisticated, targeted attack could still compromise OT systems via removable media or supply chain.
While air-gapping and physical controls significantly reduce risk, they do not eliminate it entirely, especially for sophisticated, targeted attacks. Removable media (e.g., USB drives used for updates or diagnostics) and supply chain compromises (e.g., malware embedded in legitimate software updates or new equipment) are known vectors for breaching air-gapped OT networks. The lack of updated antivirus and IDS makes these systems highly susceptible once such a breach occurs, representing the most significant residual risk.
Why the other options are wrong
- A. This is a valid observation resulting from air-gapping, but it's a *contributing factor* to the risk, not the most significant residual risk itself. The lack of updates makes the systems vulnerable *if* a threat gets in.
- C. While non-compliance is a risk, the question asks for the 'most significant residual risk' to the *information assets* and operational integrity, which is the actual compromise of the OT systems.
- D. The scenario states the OT network is 'isolated' and 'air-gapped' from the corporate IT network, making direct propagation from OT to IT unlikely.
Air-Gapped OT Network Vulnerabilities
Despite physical separation (air-gapping), operational technology (OT) networks remain vulnerable to sophisticated attacks via non-network vectors like removable media or supply chain compromises.
- Air-gapping reduces, but does not eliminate, attack vectors.
- Removable media (USB drives) are common infection points.
- Supply chain attacks can embed malware before deployment.
- Lack of internal security controls (AV, IDS) exacerbates risk post-breach.
Memory trick: Air-gaps are good, but 'Sneaky USBs' and 'Tricky Supply Chains' can still breach the 'FORTRESS'.