Intro to Patch Management in IACS Flashcards

1
Q

IACS Patching Life Cycle

A
  • Information Gathering:
    • Inventory
    • Supplier Relationships
    • Supportability
    • Assess the existing environment
    • Categorize and classify assets
  • Monitoring & Evaluation:
    • Monitor & ID patches
    • Determine Applicability
    • Risk Assessment
    • Decision
  • Patch Testing:
    • File Authenticity
    • Review Changes
    • Install Procedure
    • Qualification & Verification
    • Removal Procedure
    • Risk Mitigation
  • Patch Deployment:
    • Notification
    • Preparation
    • Scheduling
    • Deployment
  • Verification & Reporting:
    • Verification
    • Training
    • Documentation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Asset Owners requirement for Patching

A

High - Patch within 1 week
Medium - Patch within 3 months
Low - Patch within 2 years or the next available outage
None - Never

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Product Supplier or Service Provider requirement for Patching

A
  • Discovery of Vulnerabilities
  • Developement, verification & validation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Protection mechanism against Malicious code

A

Prevent, Detect, Report, Mitigate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly