003359 -Stuxnet and U.S. Incident Response
|
Points: 100 |
Case Study 1: Stuxnet and U.S. Incident Response |
||||
|
Criteria |
Unacceptable Below 60% F |
Meets Minimum Expectations 60-69% D |
Fair 70-79% C |
Proficient 80-89% B |
Exemplary 90-100% A |
|
1. Explain the role of US-CERT in protecting the nation’s industrial systems and analyze its efforts in relation to preparedness and incident and recovery management. Weight: 20% |
Did not submit or incompletely explained the role of US-CERT in protecting the nation’s industrial systems and did not submit or incompletely analyzed its efforts in relation to preparedness and incident and recovery management. |
Insufficiently explained the role of US-CERT in protecting the nation’s industrial systems and insufficiently analyzed its efforts in relation to preparedness and incident and recovery management. |
Partially explained the role of US-CERT in protecting the nation’s industrial systems and partially analyzed its efforts in relation to preparedness and incident and recovery management. |
Satisfactorily explained the role of US-CERT in protecting the nation’s industrial systems and satisfactorily analyzed its efforts in relation to preparedness and incident and recovery management. |
Thoroughly explained the role of US-CERT in protecting the nation’s industrial systems and thoroughly analyzed its efforts in relation to preparedness and incident and recovery management. |
|
2. Discuss the efforts of ICS-CERT specifically to the Stuxnet threat and examine its incident response efforts to mitigate this risk against U.S. industrial systems. Weight: 25% |
Did not submit or incompletely discussed the efforts of ICS-CERT specifically to the Stuxnet threat and did not submit or incompletely examined its incident response efforts to mitigate this risk against U.S. industrial systems. |
Insufficiently discussed the efforts of ICS-CERT specifically to the Stuxnet threat and insufficiently examined its incident response efforts to mitigate this risk against U.S. industrial systems. |
Partially discussed the efforts of ICS-CERT specifically to the Stuxnet threat and partially examined its incident response efforts to mitigate this risk against U.S. industrial systems. |
Satisfactorily discussed the efforts of ICS-CERT specifically to the Stuxnet threat and satisfactorily examined its incident response efforts to mitigate this risk against U.S. industrial systems. |
Thoroughly discussed the efforts of ICS-CERT specifically to the Stuxnet threat and thoroughly examined its incident response efforts to mitigate this risk against U.S. industrial systems. |
|
3. Determine whether or not alternate sites (e.g., hot site) are feasible for organizations that utilize ICS technologies. Provide a rationale. Weight: 20% |
Did not submit or incompletely determined whether or not alternate sites (e.g., hot site) are feasible for organizations that utilize ICS technologies. Did not submit or incompletely provided a rationale. |
Insufficiently determined whether or not alternate sites (e.g., hot site) are feasible for organizations that utilize ICS technologies. Insufficiently provided a rationale. |
Partially determined whether or not alternate sites (e.g., hot site) are feasible for organizations that utilize ICS technologies. Partially provided a rationale. |
Satisfactorily determined whether or not alternate sites (e.g., hot site) are feasible for organizations that utilize ICS technologies. Satisfactorily provided a rationale. |
Thoroughly determined whether or not alternate sites (e.g., hot site) are feasible for organizations that utilize ICS technologies. Thoroughly provided a rationale. |
|
4. Explain the high-level planning needed for an industrial systems organization that utilizes ICS technologies to prepare for attacks from cyber threats such as Stuxnet. Weight: 20% |
Did not submit or incompletely explained the high-level planning needed for an industrial systems organization that utilizes ICS technologies to prepare for attacks from cyber threats such as Stuxnet. |
Insufficiently explained the high-level planning needed for an industrial systems organization that utilizes ICS technologies to prepare for attacks from cyber threats such as Stuxnet. |
Partially explained the high-level planning needed for an industrial systems organization that utilizes ICS technologies to prepare for attacks from cyber threats such as Stuxnet. |
Satisfactorily explained the high-level planning needed for an industrial systems organization that utilizes ICS technologies to prepare for attacks from cyber threats such as Stuxnet. |
Thoroughly explained the high-level planning needed for an industrial systems organization that utilizes ICS technologies to prepare for attacks from cyber threats such as Stuxnet. |
|
Weight: 5% |
No references provided |
Does not meet the required number of references; all references poor quality choices. |
Does not meet the required number of references; some references poor quality choices. |
Meets number of required references; all references high quality choices. |
Exceeds number of required references; all references high quality choices. |
|
6. Clarity, writing mechanics, and formatting requirements Weight: 10% |
More than 8 errors present |
7-8 errors present |
5-6 errors present |
3-4 errors present |
0-2 errors present |