CRISC Information Technology and Security Practice Question
A power utility is integrating its industrial control system (ICS) with the corporate IT network to enable real-time operational data access. The risk manager identifies that the ICS uses legacy proprietary protocols without authentication. Which risk treatment option best addresses this issue while maintaining operational availability?
⚠ Common exam trap
It's easy for candidates to choose upgrading protocols (Option C) as the 'best practice' without considering the operational availability constraints of legacy ICS environments, where a unidirectional gateway provides a non-disruptive security layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a unidirectional gateway that enforces one-way data flow
A unidirectional gateway (data diode) enforces one-way data flow from the ICS to the corporate IT network, preventing any inbound traffic that could exploit the legacy protocols' lack of authentication. This maintains operational availability because the ICS remains isolated from direct network attacks while still providing real-time data access. It is the only option that addresses the authentication gap without disrupting legacy system operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement a unidirectional gateway that enforces one-way data flow
Why this is correct
A unidirectional gateway permits data to flow only from the ICS outward to corporate IT, physically preventing inbound commands or protocol exploitation. This isolates the unauthenticated legacy protocols while preserving real-time operational data access, satisfying the availability constraint without modifying the control system.
- ✗
Deploy a host-based intrusion detection system on each ICS device
Why it's wrong here
A host-based IDS only detects and alerts on malicious activity; it cannot authenticate the legacy proprietary protocol traffic, so the missing-authentication risk remains untreated. Host-based detection suits environments where endpoint compromise monitoring is the goal, not where protocol-level authentication must be added while preserving availability.
- ✗
Upgrade the ICS to modern protocols with built-in authentication
Why it's wrong here
Upgrading ICS protocols to authenticated versions requires replacing legacy field devices and controllers, causing outages incompatible with continuous power operations. Protocol modernisation is the right long-term treatment during planned plant refurbishment, but it cannot address the immediate integration risk while maintaining operational availability.
- ✗
Disconnect the ICS from the corporate network and use manual data transfer
Why it's wrong here
Disconnecting the ICS eliminates the real-time operational data access the integration exists to deliver, so it fails the availability requirement in the stem. Air-gapping with manual transfer is a valid risk treatment where no real-time connectivity is needed, such as isolated safety systems, but not here.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.