Answers
What /is /the /purpose /of /assigning /a /Target /Security /Level /(SL-T) /during /the /Assess /phase /of /ICS
/security /implementation? /- /correct /answer(s) /✔✔ /To /determine /the /existing /vulnerabilities
/of /the /system.
What /happens /during /the /Develop /& /Implement /phase /of /ICS /security /implementation? /-
/correct /answer(s) /✔✔ /Countermeasures /are /implemented /to /meet /the /Target /Security /Level
/(SL-T).
What /is /the /primary /goal /of /the /Maintain /phase /in /ICS /security /implementation? /- /correct
/answer(s) /✔✔ /To /ensure /the /Achieved /Security /Level /(SL-A) /is /equal /to /or /better /than /the
/Target /Security /Level /(SL-T).*
What /is /phase /1 /of /the /IACS /Cybersecurity /Life /Cycle? /- /correct /answer(s) /✔✔ /Assess
What /is /phase /2 /of /the /IACS /Cybersecurity /Life /Cycle? /- /correct /answer(s) /✔✔ /Develop /&
/Implement
What /is /phase /3 /of /the /IACS /Cybersecurity /Life /Cycle? /- /correct /answer(s) /✔✔ /Maintain /phase
What /is /step /1 /of /the /IACS /Cybersecurity /Life /Cycle /(Assess /Phase)? /- /correct /answer(s) /✔✔
/High-Level /Cyber /Risk /Assessment
What /is /step /2 /of /the /IACS /Cybersecurity /Life /Cycle /(Assess /Phase)? /- /correct /answer(s) /✔✔
/Allocation /of /IACS /Assets /to /Security /Zones /or /Conduits
,What /is /step /3 /of /the /IACS /Cybersecurity /Life /Cycle /(Assess /Phase)? /- /correct /answer(s) /✔✔
/Detail /Cyber /Risk /Assessment
What /is /step /4 /of /the /IACS /Cybersecurity /Life /Cycle /(Develop /& /Implement /Phase)? /- /correct
answer(s) /✔✔ /Cybersecurity /Requirements /Specification
/
What /is /step /5 /of /the /IACS /Cybersecurity /Life /Cycle /(Develop /& /Implement /Phase)? /- /correct
answer(s) /✔✔ /Design /and /engineering /of /Cybersecurity /countermeasures
/
What /is /step /6 /of /the /IACS /Cybersecurity /Life /Cycle /(Develop /& /Implement /Phase)? /- /correct
answer(s) /✔✔ /Installation, /commissioning /and /validation /of /Cybersecurity /countermeasures
/
What /is /step /7 /of /the /IACS /Cybersecurity /Life /Cycle /(Maintain)? /- /correct /answer(s) /✔✔
/Cybersecurity /Maintenance, /Monitoring /and /Management /of /Change
What /is /step /8 /of /the /IACS /Cybersecurity /Life /Cycle /(Maintain)? /- /correct /answer(s) /✔✔ /Cyber
/Incident /Response /& /Recovery
What /are /the /continuous /processes /activities /of /the /IACS /Cybersecurity /Life /Cycle? /- /correct
/answer(s) /✔✔ /Cybersecurity /Management /System: /Policies, /Procedures, /Training /&
/Awareness, /Periodic /Cybersecurity /Audits
What /must /be /done /before /an /assessment /can /be /started? /- /correct /answer(s) /✔✔ /Create /a
/Project /Plan
ID /Steps /of /the /Project /to /perform /the /assessment
ID /the /System /Under /Assessment
,System /Under /Consideration /(SUC) /- /correct /answer(s) /✔✔ /The /system /or /systems /within /an
/Industrial /Automation /and /Control /System /environment /that /are /being /evaluated /or
/designed /for /security /enhancements.
System /Under /Assessment /(SUA) /- /correct /answer(s) /✔✔ /The /system /that /is /being /evaluated
/for /compliance /with /standards.
What /are /some /required /information /gathering /items /before /the /assessment /can /begin? /-
correct /answer(s) /✔✔ /Goals /of /the /Assessment
/
IACS /asset /inventory
Understanding /of /the /IACS
Regulations, /requirements, /and /governance /of /relevance /(Government, /Industry, /Company)
Architecture /diagrams
Configuration /Files
Known /vulnerabilities
Define /roles /and /responsibilities
Establish /training /requirements
System /Architecture /Diagrams /- /correct /answer(s) /✔✔ /Depiction /of /system /components, /their
/connectivity, /and /physical /locations.
Physical /System /Architecture /Diagram /- /correct /answer(s) /✔✔ /A /diagram /that /provides /a
/visual /representation /of /the /physical /components /within /a /system /and /their
/interconnections. /It /focuses /on /hardware /elements /such /as /servers, /network /devices, /control
/systems, /and /terminals, /showing /how /these /components /are /arranged /and /connected.
Functional /System /Architecture /Diagram /- /correct /answer(s) /✔✔ /A /diagram /that /describes
/the /functions /of /a /system /and /their /relationships /without /focusing /on /physical /details. /It
, /presents /a /logical /view /of /the /system, /emphasizing /software /elements, /data /flows, /and
/interactions /between /different /functions /or /modules /within /the /system.
(True/False) /IACS /functionality /should /be /graphically /represented /on /at /least /one /IACS
Architecture /drawing /- /correct /answer(s) /✔✔ /True
/
ISA-95 /Functional /Layer /Level /0 /- /correct /answer(s) /✔✔ /The /physical /process /— /This /level
/defines /the /physical /processes /showing /data /flowing /from /sensors /and /actuators /into /the
/control /level.
ISA-95 /Functional /Layer /Level /1 /- /correct /answer(s) /✔✔ /Intelligent /devices /— /Devices /in /this
/level /sense /and /manipule /the /physical /processes. /Process, /sensors, /analyzers, /actuators /and
/related /instrumentation. /This /layer /shows /how /PLCs /receive /field /device /data, /process /it, /and
/then /send /commands /back /to /the /field /devices.
ISA-95 /Functional /Layer /Level /2 /- /correct /answer(s) /✔✔ /Control /systems /— /Supervising,
/monitoring /and /controlling /the /physical /processes. /Real-time /controls /and /software; /DCS,
/human-machine /interface /(HMI); /supervisory /and /data /acquisition /(SCADA) /software. /This
/level /represents /how /the /control /systems /manage /PLCs, /how /operator /commands /are
/processed, /and /how /alarm /conditions /are /handled.
ISA-95 /Functional /Layer /Level /3 /- /correct /answer(s) /✔✔ /Manufacturing /operations /systems /—
/Managing /production /workflow /to /produce /the /desired /products. /Batch /management;
/manufacturing /execution/operations /management /systems /(MES/MOMS); /laboratory,
/maintenance /and /plant /performance /management /systems; /data /historians /and /related
/middleware. /Time /frame: /shifts, /hours, /minutes, /seconds.
ISA-95 /Functional /Layer /Level /4 /- /correct /answer(s) /✔✔ /Business /logistics /systems /—
/Managing /the /business-related /activities /of /the /manufacturing /operation. /ERP /is /the /primary
/system; /establishes /the /basic /plant /production /schedule, /material /use, /shipping /and
/inventory /levels. /Time /frame: /months, /weeks, /days, /shifts. /This /level /shows /how /enterprise