A team is drafting its first OT incident response plan after years of relying on the corporate IT IR playbook. Which foundational difference should reshape the plan more than any other?
- A.Maintaining safe physical process operation can outrank both data confidentiality and forensic evidence preservation
- B.OT incidents are always caused by external nation-state actors rather than insiders
- C.OT systems can be patched and rebooted faster than IT systems during an incident
- D.Encryption of network traffic is the dominant control during OT incident handling
Why A is correct
IT IR plans typically prioritize confidentiality, integrity, and evidence preservation, but OT environments add safety and continuous, safe physical operation as overriding concerns. A plan copied straight from IT will mishandle situations where pulling a device for forensics could endanger people or the process.
Know someone studying for OT Security Fundamentals? Send them this one.