Two engineering laptops are used: one is locked into the OT zone and never leaves, the other is a general-purpose corporate laptop. Why does sound architecture forbid using the corporate laptop to program controllers?
- A.A roaming corporate laptop can carry malware acquired on the IT side or internet directly into the control zone, bridging the boundary
- B.Corporate laptops are too slow to run engineering software
- C.Corporate laptops cannot physically connect to industrial switches
- D.Programming controllers requires a desktop, not a laptop
Why A is correct
A general-purpose laptop that roams across networks and the internet can pick up malware and then deliver it straight into the control zone when used to program controllers, acting as a transient bridge. Dedicated, zone-locked engineering devices reduce this cross-domain contamination risk.
Know someone studying for OT Security Fundamentals? Send them this one.