Intro to Patch Management in IACS Flashcards
1
Q
IACS Patching Life Cycle
A
- Information Gathering:
- Inventory
- Supplier Relationships
- Supportability
- Assess the existing environment
- Categorize and classify assets
- Monitoring & Evaluation:
- Monitor & ID patches
- Determine Applicability
- Risk Assessment
- Decision
- Patch Testing:
- File Authenticity
- Review Changes
- Install Procedure
- Qualification & Verification
- Removal Procedure
- Risk Mitigation
- Patch Deployment:
- Notification
- Preparation
- Scheduling
- Deployment
- Verification & Reporting:
- Verification
- Training
- Documentation
2
Q
Asset Owners requirement for Patching
A
High - Patch within 1 week
Medium - Patch within 3 months
Low - Patch within 2 years or the next available outage
None - Never
3
Q
Product Supplier or Service Provider requirement for Patching
A
- Discovery of Vulnerabilities
- Developement, verification & validation
4
Q
Protection mechanism against Malicious code
A
Prevent, Detect, Report, Mitigate