A utility asks why NIST SP 800-61 treats preparation as part of the cycle rather than a one-time project. Which answer reflects OT practice?
- A.Attack methods stay fixed after the first review
- B.Backups need no refresh once the first copy is verified
- C.The plan text is fixed once the regulator accepts it
- D.Logic edits plus staff changes outdate baselines
Why D is correct
OT environments change through logic edits, new devices and staff turnover, so baselines and backups need refreshing to be usable in a real event. The other reasons are invented requirements.
Know someone studying for OT Security Fundamentals? Send them this one.