Two engineering laptops are used: one is locked into the OT zone and never leaves, the other is a general-purpose corporate laptop.
Why does sound architecture forbid using the corporate laptop to program controllers?
- A.Corporate laptops are too slow to run engineering software because vendor programming suites demand more RAM than a business laptop carries
- B.A roaming corporate laptop can carry malware acquired on the IT side or internet directly into the control zone, bridging the boundary
- C.Corporate laptops cannot physically connect to industrial switches, a property formally verified for every commercial implementation and re-attested with each firmware release
- D.Programming controllers requires a desktop, not a laptop
Why B is correct
A general-purpose laptop that roams across networks and the internet can pick up malware and then deliver it straight into the control zone when used to program controllers, acting as a transient bridge. Dedicated, zone-locked engineering devices reduce this cross-domain contamination risk.
Know someone studying for OT Security Fundamentals? Send them this one.