skip to content

A plant manager must sign that an IPS rule may stop the line to block an intruder - what belongs in that proposal?

level: principalimportance: nice to knowfreq 32%

answer

  1. two outages, one set of units
  2. scoped, timed, reversible versus none of those
  3. who can revoke it at three in the morning
  4. narrow the ask until it is signable
  5. a refusal is a recorded accepted risk

basics

~20 s

Everything needed to compare two outages in one set of units: the exposure if the intruder is not blocked, the worst credible wrong drop and its cost per minute, the exact rules enforced, and who can revoke it how fast.

solid answer

~50 s

The proposal is not a security document; it is a comparison of two ways the line can stop. State the exposure in his terms - this traffic has crossed into the plant repeatedly, the controllers behind it cannot be patched, and a successful intrusion stops production for longer and less predictably than any wrong drop. State the worst credible wrong outcome concretely: which legitimate flows the enumerated rules could sever, what a severed flow does to a running batch, recovery time, cost per minute. Keep the scope small enough to be signable - named rules, one segment, one direction, a review date. Name who can revoke enforcement, how fast, and who answers the phone at three in the morning. And write down the alternative: if he declines, the organisation is accepting continued intrusion attempts against unpatchable equipment, with his name on that choice rather than yours.

go deeper

for a junior

Understand that turning on blocking where equipment cannot tolerate interruption is somebody else's decision to make, and that the security engineer prepares it rather than takes it.

for a middle

Be able to list what such a proposal must contain: exact rules, segment and direction, the flows that could be severed, the revocation path and the review date.

for a senior

Show you can price both outcomes in the operations owner's units and design the ask - narrow scope, fast revocation - so that it is actually grantable rather than technically correct and refused.

for a principal

Own the standard for the whole estate: who may sign for enforcement, what evidence a signature requires, how refusals are recorded as accepted exposures, and how the organisation avoids a decade of controls stuck in alert mode.

## Why this is a signature and not a change ticket Enforcement moves an error budget from the security team to the operations owner. He is the one whose currency the mistakes are paid in, he is accountable for output or for patient safety, and he can say no. That makes this a decision he owns and you prepare - and preparing it well is most of the job, because most estates never finish turning blocking on for exactly this reason: nobody ever puts the choice in front of the person who could actually make it. ## Translate into his units Security language does not survive contact with a production meeting. Two outages are being compared: | | If we enforce and are wrong | If we do not enforce and they succeed | |---|---|---| | Trigger | a legitimate flow matches the rule | an intrusion reaches unpatchable equipment | | Duration | until someone revokes the rule | until the equipment is restored, which is slower | | Predictability | we choose when to expose ourselves | the adversary chooses | | Blast radius | the flows the enumerated rules touch | whatever the compromised segment reaches | | Who is on the hook | both of us, by prior agreement | both of us, without one | The honest asymmetry that carries the argument is predictability, not probability. You are not claiming enforcement is risk-free; you are claiming its risk is scoped, timed and reversible while the other is none of those. ## What has to be in the document 1. **Exactly what is enforced.** Named rules, one segment, one direction, in a sentence a non-specialist can read back. Not a category name. 2. **The exposure, evidenced.** How often this traffic has arrived, over what period, and what it was trying to reach. Concrete, and not inflated - a manager who catches one exaggeration stops reading. 3. **The worst credible wrong outcome.** Which legitimate flows could match, what a severed flow does to work in progress, whether it is a restart or a manual intervention, recovery time, cost per minute or the clinical equivalent. 4. **Revocation.** Who is authorised to turn it off, how quickly, without waiting for a change window, and which phone number is answered at three in the morning. A manager signs risk he can stop. 5. **Scope limit and review date.** The signature covers this rule set, on this segment, until this date. Anything added later is a new signature. 6. **The alternative, stated plainly.** If he declines, that is a legitimate outcome, but it must be recorded as an accepted exposure with his name on it - not filed as a security shortfall. ## When he says no And he often will, at first. Two responses are professional and one is not. - **Narrow the scope until it is signable.** Fewer rules, one direction, the segment with the least work in progress. A small enforced set that survives is worth more than a large one that is reverted after the first incident and never tried again. - **Take the refusal as a decision and record it.** Compensating measures continue, the exposure stays on the register with an owner and a date, and the question is reopened when the exposure changes. - **Not professional:** enforcing anyway on the strength of a change ticket, or leaving the refusal undocumented so that the next intrusion becomes an argument about who knew what. ## What an interviewer is listening for That you know the decision is not yours; that you can price both outcomes in the other person's units; that your ask is narrow enough to be granted; that revocation is designed before enforcement is; and that a refusal produces a recorded accepted risk rather than a grudge. Candidates who answer this purely technically - talking about tuning and thresholds - reveal that they have never had to get a signature from someone who could refuse.

  • The manager refuses outright. What is the correct next move?
    Treat the refusal as a decision, not a failure. Record it as an accepted exposure with his name, the date and the reasoning, keep the detection running, and narrow the ask to whatever subset he would sign - fewer rules, one direction, the least critical segment. Then set a trigger to reopen it: a new intrusion attempt, a device class change, or the review date, whichever comes first.
  • Why does revocation belong in the proposal rather than in the runbook afterwards?
    Because it is what makes the risk signable. A manager is agreeing to an outage risk he can stop; if stopping it requires a change window or a person who may be asleep, he is really being asked to accept an unbounded one. Naming the authorised revoker and the response time converts an open-ended commitment into a bounded one, which is usually the difference between a signature and a refusal.

saying these in an interview costs you the question

  • Argues the case in security units, not production units
  • Asks for a whole rule category in one signature
  • Has no revocation path or named owner
  • Treats a refusal as a security failure to escalate
  • Claims enforcement carries no outage risk

context