Telecom and hardware vendors dial into municipal SCADA support modems with no monitoring or access constraints. What should the security architect require for third-party connectivity?
Select an answer to reveal the explanation.
Short Explanation
An unwatched support modem into SCADA is a side door into the plant floor. Park vendors on an approved, logged gateway with their own credentials, MFA when you can, and a clock that ends the session—don’t leave open dial-ins or one forever password for every OEM. Public phone lists and permanent shared accounts just widen the blast radius.
Full Explanation
Third-party connectivity into operational technology must be mediated, authenticated, time-bounded, and audited. Unmanaged dial-up or direct modem access into SCADA bypasses network monitoring and creates persistent external entry points. Approved remote-access gateways with unique identities, multifactor authentication where feasible, and comprehensive logging align vendor support with secure channel and third-party connectivity requirements. Shared permanent accounts and public exposure of access numbers increase credential theft and unauthorized use risk.