Soru

Zorluk: ZorSecure Network Design and Segmentation

An industrial manufacturing plant operates a Safety Instrumented System (SIS) to control physical emergency shutdown valves. The security architecture team must forward real-time operational telemetry from the SIS domain to a cloud-based enterprise monitoring platform. However, regulatory standards mandate that no network path can exist that allows incoming commands or external traffic to reach the safety controllers under any circumstances. Which of the following network segmentation controls best satisfies this requirement?

  1. A physical data diode deployed at the boundary between the OT network collectors and the enterprise networkCevap
  2. B
    A dual-homed jump box situated within a converged IT/OT demilitarized zone (DMZ) utilizing multi-factor authentication
  3. C
    Private VLANs (pVLANs) configured across shared core switches with strict layer 3 access control lists (ACLs)
  4. D
    A stateful next-generation firewall (NGFW) inspecting all North-South traffic passing into the safety environment

Cevap

Deploying a physical data diode at the boundary between the operational technology collectors and the enterprise network is the optimal solution.
A physical data diode uses hardware-level mechanisms (such as an LED pointing to a photo-receiver across an optical gap) to enforce unidirectional communication at Layer 1. This physical design ensures that telemetry can be sent to the enterprise network while rendering inbound signal transmission physically impossible, fully satisfying the requirement to prevent external command injection into safety controllers.

Adım Adım Çözüm

1
Analyze the functional and security requirements of the scenario
Telemetry data must flow outbound from the Safety Instrumented System (SIS) to the enterprise platform, but absolute isolation against inbound traffic/commands must be guaranteed.
Safety Instrumented Systems control critical physical processes where unintended software command injection could cause physical harm or infrastructure failure.
2
Evaluate candidate network segmentation controls against the strict non-reversibility requirement
Software controls (firewalls, jump boxes, pVLANs) maintain bidirectional logical capabilities or stateful session return channels.
Any software-defined control can potentially be bypassed via zero-day vulnerabilities, configuration errors, or session exploitation.
3
Identify the hardware-enforced unidirectional isolation mechanism
A physical data diode allows optical transmission in only one direction while lacking physical receiving hardware on the sender side.
This guarantees at the physical layer (Layer 1) that return traffic, acknowledgments, or inbound exploits cannot travel backward into the safety zone.

Anahtar Kavram

Unidirectional Data Diodes and Industrial Control System (ICS/OT) Microsegmentation
Tahmini Süre:2m 0s
Bu soruyu puanla