ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium

A CISA is auditing the endpoint security controls of a manufacturing company. The company operates an Operational Technology (OT) network that controls industrial machinery, which is air-gapped from the corporate IT network. However, engineers occasionally use USB drives to transfer firmware updates and diagnostic logs between the IT network (where updates are downloaded) and the OT network. What is the MOST significant security vulnerability introduced by this practice?

  1. AIncreased risk of data exfiltration from the OT network.
  2. BHigher operational costs due to manual data transfer.
  3. CDifficulty in applying security patches to OT devices.
  4. DPotential for malware from the IT network to infect the air-gapped OT network.
Show answer & explanation

Correct answer: D. Potential for malware from the IT network to infect the air-gapped OT network.

The use of USB drives to bridge an air-gapped network bypasses the fundamental security control of air-gapping. This creates a direct conduit for malware, potentially picked up from the less secure IT network, to infect critical industrial control systems on the OT network, leading to operational disruption or damage.

Why the other options are wrong

  • A. While possible, the primary purpose of air-gapping is to prevent ingress. Malware from IT to OT is a more direct and severe threat in this context.
  • B. Increased costs are operational concerns, not the most significant security vulnerability.
  • C. This practice is a method for applying updates, not a difficulty. The issue is the security of the method itself.

Air-Gapped OT Network Vulnerabilities

Security weaknesses in Operational Technology (OT) networks that are physically isolated (air-gapped) from IT networks, often arising from manual data transfer methods that bypass the air gap.

  • Air-gapping aims to prevent network-based attacks.
  • Physical media (e.g., USB drives) can bridge air gaps.
  • Malware transfer is a significant risk when air gaps are compromised.

Memory trick: Don't bring a Trojan horse through the 'airlock' with your data.

More Domain 5: Protection of Information Assets questions