ICS Incident Response Tabletops Flashcards

1
Q

Questions to ask on preparedness

A

Resilience against ransomware, are critical assets protected, can you run the ICS process in manual mode or completely isolated from the IT network?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

ICS IR Tabletop Planing

A

1.) Know Teams 2.) Who is responsible 3.) Communication (Internal and external) 4.) Defensible Cyber Position (Isolation)…

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Tabletop Benefits

A

Validate Readiness, Awareness, Improved Detection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How to run tabletops

A

Planning, Teams, Scenarios, Run Time, Close Gaps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Tabletop Scenarios

A

1.) Ransomware on ICS or IT 2.) HMI Activity 3.) ICS Protocol Abuse 4.) IT–> ICS/OT Trust Abuse 5.) Physical Access attack.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Ransomware on ICS or IT

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly