ICS Incident Response Tabletops Flashcards
1
Q
Questions to ask on preparedness
A
Resilience against ransomware, are critical assets protected, can you run the ICS process in manual mode or completely isolated from the IT network?
2
Q
ICS IR Tabletop Planing
A
1.) Know Teams 2.) Who is responsible 3.) Communication (Internal and external) 4.) Defensible Cyber Position (Isolation)…
3
Q
Tabletop Benefits
A
Validate Readiness, Awareness, Improved Detection
4
Q
How to run tabletops
A
Planning, Teams, Scenarios, Run Time, Close Gaps
5
Q
Tabletop Scenarios
A
1.) Ransomware on ICS or IT 2.) HMI Activity 3.) ICS Protocol Abuse 4.) IT–> ICS/OT Trust Abuse 5.) Physical Access attack.
6
Q
Ransomware on ICS or IT
A