An organization is in the process of integrating its operational technology and information technology areas. As part of the integration, some of the cultural aspects it would like to see include more efficient use of resources during change windows, better protection of critical infrastructure, and the ability to respond to incidents. The following observations have been identified:
The ICS supplier has specified that any software installed will result in lack of support.
There is no documented trust boundary defined between the SCADA and corporate networks.
Operational technology staff have to manage the SCADA equipment via the engineering workstation.
There is a lack of understanding of what is within the SCADA network.
Which of the following capabilities would BEST improve the security position?
- A: VNC, router, and HIPS
- B: SIEM, VPN, and firewall
- C: Proxy, VPN, and WAF
- D: IDS, NAC, and log monitoring