ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsHard

A critical infrastructure organization operates a Supervisory Control and Data Acquisition (SCADA) system that manages essential power grid operations. Due to the real-time nature and high availability requirements of the SCADA components, traditional patch management cycles are often not feasible, and system reboots can cause unacceptable downtime. Which of the following is the MOST appropriate security measure to mitigate vulnerabilities in such an environment?

  1. AIsolating the SCADA network with strict firewall rules and a demilitarized zone (DMZ).
  2. BImplementing daily full system backups for rapid recovery.
  3. CPerforming continuous vulnerability scanning on production SCADA systems.
  4. DUpgrading all SCADA components to the latest operating system versions immediately.
Show answer & explanation

Correct answer: A. Isolating the SCADA network with strict firewall rules and a demilitarized zone (DMZ).

For highly sensitive and available systems like SCADA, where patching and reboots are problematic, network segmentation and isolation are critical. Strict firewall rules and a DMZ create a strong perimeter, limiting external access to the SCADA network and reducing the attack surface, thereby mitigating vulnerabilities even if they cannot be patched immediately.

Why the other options are wrong

  • B. Backups are crucial for recovery, but they don't *mitigate* the vulnerability itself or prevent an attack from occurring in the first place.
  • C. Continuous vulnerability scanning on *production* SCADA systems can introduce instability or even disrupt operations due to their delicate nature, and it only identifies vulnerabilities, not mitigates them.
  • D. Immediately upgrading operating systems is often not feasible in SCADA environments due to compatibility issues, rigorous testing requirements, and the high risk of downtime, making it an impractical solution.

SCADA Security

Securing SCADA (Supervisory Control and Data Acquisition) systems involves unique challenges due to their critical function, real-time operation, legacy components, and high availability demands. Network segmentation, strong access controls, and robust monitoring are key.

  • High availability and real-time operations are paramount.
  • Patching and reboots can be disruptive and are often avoided.
  • Network segmentation and isolation are crucial for protection.
  • Often involves legacy systems with known vulnerabilities.

Memory trick: Isolate the heart of the grid.

More Security Operations questions