101
ICs VuLnerABILItIes
on the IT business network with minimum or sometimes no
separation at all: not even logical separation with dierent
subnets. While physically distinct networks for ICS and IT
are not generally practical or desirable, a variety of logical seg-
regation techniques can be applied. e danger with weak or
no segregation is that malware and malicious entities in the
relatively open IT business network “hop” unopposed into the
ICS network.
• Separation of duties for administrative accounts and roles—
Within the ICS network, administrative eciency often
encourages poor security practices, such as sharing admin-
istrator accounts, complete overlap of administrative duties,
and common passwords. In the event of an ...