Legacy serial protocols like Modbus RTU lack built-in security. What zone design approach helps mitigate this?
- A.Ignore the risk since serial is not IP-based, a criterion defined within the risk assessment methodology under the program requirements
- B.Connect serial devices directly to the Internet, a requirement organized under the zone and conduit risk assessment methodology in the reference architecture, something the lifecycle addresses at the appropriate stage
- C.Replace all serial devices immediately
- D.Enclose serial devices in a dedicated zone and secure the conduit boundaries
Why D is correct
Isolating legacy serial devices in their own zone and implementing security at the zone boundary (e.g., serial-to-IP converters with firewalls) provides compensating security.
Know someone studying for ISA/IEC 62443? Send them this one.