IoT & Supply chain attacks Flashcards
1
Q
security vs safety
A
safety: protection against random incidents
security: protection against intended incidents planned by an attacker
2
Q
Consequences of Complex adaptive systems CAS
A
- new & innovative attacks
- predictability of attacks decreases
- remote effects: increased attacks on subsystems and suppliers
3
Q
Terminology OT/IT/IOT/IIOT/ISC
A
- IT Information Technology: entire spectrum of technology for information processing
- OT Operational Technology: Hardware and software that controls physical devices
- ISC Industrial Control Systems: monitoring and controlling physical industrial processes
- IoT Internet of Things: global network of smart physical objects
- IIoT Internet of Industrial Things: Subset of IoT specific industry
4
Q
IT vs OT requirements
A
IT: confidentiality & Integrity are crucial, availability is only important, rapid response to threats, easily updated
OT: availability and integrity is crucial, confidentiality not, slow response to threats, legacy or unsupported infrastructure
5
Q
Novel Attacks & Risks, Ex
A
Strava heatmap reveals sensitive info about military bases and details about service members
6
Q
Cyber Safety norms
A
- define criteria to identify critical goods
- develop min. integrity and security requ.
- provide standard contractual security agreement for suppliers of crit. goods. eg. accounts must be declared, bug bounty programm
- testing