Skip to main content

Pro audit program · v1.0

Safety Systems & Vendor Remote Access

Safety Instrumented Systems (SIS) and vendor remote access are the two paths most likely to take a plant offline. Targeted audit.

  • General target area
  • ISA/IEC 62443 framework
  • 7 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

Safety Instrumented Systems (SIS) and vendor remote access are the two paths most likely to take a plant offline. Targeted audit.

Risks addressed

  • Critical SIS reachable from process-control network
  • Critical Vendor remote session has standing always-on access
  • Critical No alerting when safety logic is modified

Controls (7)

  1. SIS air-gapped or strongly segmented

    Critical

    Safety Instrumented Systems (SIS) in industrial control environments must be physically or logically isolated from enterprise IT networks and other operational technology (OT) zones to prevent unauthorized access and cyber threats. Air-gapping creates a complete physical separation with no network…

    How to test + evidence

    Testing procedure: SIS on its own zone; only diode / one-way flow out for monitoring.

    Evidence to collect: Network diagram + ACL export.

  2. SIS write-protect (key-switch / engineering mode)

    Critical

    Safety Instrumented System (SIS) write-protect controls prevent unauthorized modification of critical safety logic by requiring physical key-switch activation or engineering mode authorization before configuration changes can be made. When engaged, the control locks programmable logic controllers (PLCs), safety controllers, and…

    How to test + evidence

    Testing procedure: Engineering keys held by named individuals; default state is run / write-protected.

    Evidence to collect: Photo + custody log.

  3. Alerting on safety-logic changes

    Critical

    This control establishes real-time monitoring and alerting mechanisms that trigger notifications whenever safety-critical logic—such as industrial control system (ICS) ladder logic, safety instrumented system (SIS) code, or operational technology (OT) firmware—is modified, uploaded, or deleted. Alerts are generated automatically based…

    How to test + evidence

    Testing procedure: Any logic change generates a high-priority alert + ticket.

    Evidence to collect: Alert config + last alert.

  4. Vendor remote access is time-bound + ticketed

    Critical

    This control ensures that third-party vendors and service providers are granted remote access to organizational systems only for explicitly defined time periods and through a formal ticketing or request mechanism. Access is provisioned based on documented business need, automatically expires…

    How to test + evidence

    Testing procedure: Per-session approval; access window expires automatically.

    Evidence to collect: Ticket + session log sample.

  5. Vendor session recording

    High

    Vendor session recording captures and retains video, audio, and screen activity for privileged third-party users accessing organizational systems, typically via remote support sessions, VDI environments, or jump hosts. This control creates an auditable trail of vendor actions during maintenance, troubleshooting,…

    How to test + evidence

    Testing procedure: Privileged session recording captures every vendor connection.

    Evidence to collect: PSM tool config + sample recording.

  6. Annual safety + cyber joint review

    Medium

    This control requires an annual structured review meeting between physical safety and cybersecurity teams to identify overlaps, dependencies, and cross-domain risks at the intersection of industrial control systems, physical access, and digital infrastructure. The joint review assesses whether safety-critical systems…

    How to test + evidence

    Testing procedure: Process safety + cyber owners jointly review every 12 months.

    Evidence to collect: Review minutes.

  7. Tabletop exercise covering OT incident

    High

    A tabletop exercise covering operational technology (OT) incident response is a structured, discussion-based simulation where key personnel walk through their response to a realistic OT-specific security scenario, such as ransomware affecting SCADA systems, HMI compromise, or PLC manipulation. Unlike traditional…

    How to test + evidence

    Testing procedure: IR tabletop scenario includes OT impact + safety implications.

    Evidence to collect: Tabletop AAR.