Skip to main content

Pro audit program · v1.0

Safety Systems & Vendor Remote Access

Safety Instrumented Systems (SIS) and vendor remote access are the two paths most likely to take a plant offline. Targeted audit.

  • General target area
  • ISA/IEC 62443 framework
  • 7 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

Safety Instrumented Systems (SIS) and vendor remote access are the two paths most likely to take a plant offline. Targeted audit.

Risks addressed

  • Critical SIS reachable from process-control network
  • Critical Vendor remote session has standing always-on access
  • Critical No alerting when safety logic is modified

Controls (7)

  1. SIS air-gapped or strongly segmented

    Critical

    SIS air-gapped or strongly segmented

    How to test + evidence

    Testing procedure: SIS on its own zone; only diode / one-way flow out for monitoring.

    Evidence to collect: Network diagram + ACL export.

  2. SIS write-protect (key-switch / engineering mode)

    Critical

    SIS write-protect (key-switch / engineering mode)

    How to test + evidence

    Testing procedure: Engineering keys held by named individuals; default state is run / write-protected.

    Evidence to collect: Photo + custody log.

  3. Alerting on safety-logic changes

    Critical

    Alerting on safety-logic changes

    How to test + evidence

    Testing procedure: Any logic change generates a high-priority alert + ticket.

    Evidence to collect: Alert config + last alert.

  4. Vendor remote access is time-bound + ticketed

    Critical

    Vendor remote access is time-bound + ticketed

    How to test + evidence

    Testing procedure: Per-session approval; access window expires automatically.

    Evidence to collect: Ticket + session log sample.

  5. Vendor session recording

    High

    Vendor session recording

    How to test + evidence

    Testing procedure: Privileged session recording captures every vendor connection.

    Evidence to collect: PSM tool config + sample recording.

  6. Annual safety + cyber joint review

    Medium

    Annual safety + cyber joint review

    How to test + evidence

    Testing procedure: Process safety + cyber owners jointly review every 12 months.

    Evidence to collect: Review minutes.

  7. Tabletop exercise covering OT incident

    High

    Tabletop exercise covering OT incident

    How to test + evidence

    Testing procedure: IR tabletop scenario includes OT impact + safety implications.

    Evidence to collect: Tabletop AAR.