Full Coverage
Traffic camera is only deployed at risky locations to detect unsafe driving behavior but not everywhere
This time, I talk about auditor instead of cybersecurity practitioner that I have come across.
In an ICS audit, auditor has questioned why the deployed anomalies detection does not have full coverage of all devices. This will impose cyber risks due to malicious traffic cannot be detect early.
Despite thorough elaboration with the following rationales, auditor is still not satisfied:
The ICS is isolated from the Internet and not even any other peer ICSWithin the ICS, the plant units are further zoned in the network such that cyber threats are contained prohibiting lateral movement to compromise the entire ICSThe ICS is hardened with removable media lock downOutgoing process information data to other the repository in the ICS network is thru unidirectional gateway enforcing push out to avoid reverse TCP attack in the case of stateful network firewallFull coverage will have only very a small gain in detection capability...