About this program
Inventory for OT looks nothing like IT. Quick check on coverage, criticality, vendor-approved patch windows and risk-acceptance for unpatchable assets.
Risks addressed
- High Unknown assets in OT u2014 invisible CVE exposure
- High Vendor will not certify recent patches u2014 stuck on old firmware
- Critical Critical safety asset patched, breaks the certification
Controls (6)
-
Passive OT asset discovery in place
HighPassive OT asset discovery uses network monitoring techniques such as span ports, network taps, or inline sensors to identify industrial control systems, PLCs, HMIs, SCADA devices, and other operational technology assets without transmitting packets to or actively probing those devices.…
How to test + evidence
Testing procedure: Tool (Claroty / Dragos / Nozomi / equivalent) passively inventories OT assets.
Evidence to collect: Tool inventory output.
-
Criticality + safety classification per asset
HighThis control requires the organization to assign a criticality level and safety impact classification to each information system asset, infrastructure component, and data repository based on operational importance, confidentiality requirements, and potential impact to human safety or public welfare. Classifications…
How to test + evidence
Testing procedure: Each asset tagged: safety-critical, operations-critical, support.
Evidence to collect: Asset register.
-
Vendor patch approval workflow documented
HighThis control ensures a documented, repeatable workflow governs how vendor-supplied patches are evaluated, approved, and authorized for deployment in production environments. The workflow typically includes security review, compatibility testing, change approval board sign-off, and rollback planning before patches are applied…
How to test + evidence
Testing procedure: Each vendor patch approval matrix on file: what they certify, what they do not.
Evidence to collect: Vendor matrix.
-
Risk acceptance for unpatchable assets
MediumThis control governs the formal acceptance of residual risk for assets that cannot be patched due to technical constraints, vendor end-of-life, operational dependencies, or compatibility limitations. It requires documented justification, compensating controls, and time-bound authorization by senior management or a…
How to test + evidence
Testing procedure: Compensating controls documented; risk owner signed off.
Evidence to collect: Risk register.
-
Change-window calendar with operations
HighA change-window calendar integrated with operations establishes a centralized, documented schedule that coordinates when changes may be deployed to production systems, accounting for operational constraints, business-critical periods, and resource availability. This control ensures that IT operations teams, change management boards,…
How to test + evidence
Testing procedure: Patching only during agreed maintenance windows; emergency overrides require approval.
Evidence to collect: Change calendar.
-
Backup of PLC / HMI logic with restore tested
CriticalThis control requires organizations to maintain current backup copies of Programmable Logic Controller (PLC) and Human-Machine Interface (HMI) logic, configuration files, and ladder logic programs, and to periodically test restoration procedures to verify recoverability. Backups must be versioned, stored securely…
How to test + evidence
Testing procedure: Logic backups + last successful restore test on a sample device.
Evidence to collect: Backup + restore test report.