A control engineer asks why the OT IR plan lists "return-to-service verification" as a distinct step after recovery. What is the rationale?
- A.To confirm restored control systems behave correctly and safely before resuming full production
- B.To generate billing records for the incident
- C.To permanently archive the compromised disk images
- D.To notify shareholders of the incident outcome
Why A is correct
Restoring a control system from backup is not enough; responders must verify that setpoints, logic, and I/O behave correctly and safely before the process is handed back to operations. This verification step prevents a faulty restoration from causing a process upset.
Know someone studying for OT Security Fundamentals? Send them this one.