An operator wants to copy a configuration file from a USB stick directly into an HMI on the production floor. What practice best balances usability with malware-introduction risk?
- A.Route all removable media through a dedicated scanning kiosk that sanitizes and validates files before they are transferred to control hosts on controlled media
- B.Disable antivirus on the HMI so the file copy is not delayed
- C.Permit personal USB drives but require operators to sign a usage logbook
- D.Allow any USB device on HMIs as long as it is reformatted first at the HMI
Why A is correct
Removable media is a leading malware vector into air-gapped or segmented OT networks. A media-sanitization kiosk scans and validates content before it reaches control hosts, while uncontrolled or personal USB use bypasses that defense entirely.
Know someone studying for OT Security Fundamentals? Send them this one.