What is the PRIMARY consideration when testing industrial control systems (ICS) for security weaknesses?
Correct Answer: D
The primary consideration when testing industrial control systems (ICS) for security weaknesses is that ICS are often sensitive to unexpected traffic. ICS are systems that monitor and control physical processes, such as power generation, water distribution, or manufacturing. ICS are often designed for high availability, reliability, and safety, but not necessarily for security. ICS may use legacy protocols, devices, or software that are not compatible with modern security tools or standards. ICS may also have strict timing or performance requirements that could be disrupted by network scanning, penetration testing, or other security activities.
Therefore, testing ICS for security weaknesses requires careful planning, coordination, and authorization to avoid causing adverse effects on the ICS operations or safety. References: CISSP All-in-One Exam Guide, Chapter 4: Communication and Network Security, Section: Industrial Control Systems, pp. 287-288.