CISA Industrial Control Systems (ICS) Security Guidance
Evidence request list. 16 controls, 16 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
CISA ICS: Defense-in-Depth Recommended Practice
Integrate ICS cybersecurity risk into a multitier (organisation, mission/business, system) risk-management approach tailored to the operational-technology context and its safety, reliability and availability priorities.
- ICS cyber risk-management approach integrated across organisation/mission/system tiers
- Risk register reflecting OT safety and availability priorities
- IT risk process applied to OT without tailoring
- No OT representation in enterprise risk management
Maintain an inventory of ICS assets, categorise asset criticality, identify security risks, determine potential impact, tailor and implement security controls, and monitor and adjust. The inventory is the basis for patching, segmentation and risk characterisation.
- Current ICS/OT asset inventory with criticality categorisation
- Risk characterisation and impact determination per asset class
- Control-tailoring and monitor/adjust records
- Incomplete or stale OT asset inventory
- Criticality not assessed
Protect physical access to ICS assets, control centres, field devices, network equipment and cabling, recognising that physical access often defeats logical controls in OT environments.
- Physical access controls for control centres and field/equipment locations
- Monitoring of physical access to OT assets
- Unsecured field devices/cabinets
- No physical access logging for control rooms
Design ICS network architecture using defined zones, a demilitarised zone (DMZ) between the control network and the corporate/enterprise network, and VLAN segmentation to separate functions and contain compromise.
- Zoned ICS network architecture diagram with an IT/OT DMZ
- VLAN segmentation of control functions
- No DMZ between corporate and control networks
- Unsegmented control LAN
Implement layered security architecture: perimeter security, firewalls between zones, unidirectional gateways/diodes where appropriate, access and authentication controls, and restrictions on bring-your-own-device.
- Firewall rulebase between corporate, DMZ and control zones
- Unidirectional gateway/diode deployment where applicable
- BYOD restriction policy for the control environment
- Permissive firewall rules into the control zone
- Personal devices permitted on OT networks
Harden ICS hosts through patch and vulnerability management, securing of field devices, and security of virtual machines used in the control environment.
- Host hardening baselines for servers, workstations and field devices
- Patch/vulnerability management for OT hosts and VMs
- Unhardened HMI/engineering hosts
- Field devices excluded from vulnerability management
Deploy security monitoring across the ICS: intrusion detection and prevention systems suited to OT protocols, security audit logging, and security incident and event monitoring (SIEM) to detect and correlate adversarial activity.
- OT-aware IDS/IPS coverage
- Security audit logging from ICS assets forwarded to monitoring
- SIEM correlation and alerting for the control environment
- No monitoring of OT protocols
- ICS logs not collected or reviewed
Manage vendor and supply-chain security for ICS components, including integrator and maintenance-provider security, third-party access, and provenance of hardware/software/patches.
- Vendor/integrator security requirements and assessments
- Supply-chain provenance and patch-authenticity controls for ICS components
- Control over third-party/maintenance access
- No security requirements on integrators/vendors
- Unverified component or patch provenance
Address the human element through security awareness, role-based training for operators and engineers, and policies that reduce social-engineering and insider risk in the control environment.
- Role-based ICS security awareness and training programme
- Policies addressing social engineering and insider risk
- No OT-specific security training
- Operators unaware of cyber threats
CISA ICS: Seven Steps to Effectively Defend ICS
Deploy application allowlisting (AWL) to detect and prevent execution of malware uploaded by adversaries; static systems such as HMI computers and database servers are ideal candidates. Baseline and calibrate AWL deployments in cooperation with the control-system vendor.
- Application allowlisting deployed on HMI/database/static hosts
- AWL baseline and exception process agreed with the vendor
- Alerts on blocked-execution events
- AWL absent on HMI/engineering hosts
- Reliance on signature antivirus only
Run a configuration/patch management program built on an accurate baseline and asset inventory, prioritising PC-architecture machines (HMI, database server, engineering workstation roles). Limit connection of external laptops, prefer known-good vendor laptops, and test updates on an isolated system with malware detection before operational deployment. Obtain updates from authenticated vendor sites and validate authenticity via digital signatures or out-of-band hashes.
- ICS patch/configuration baseline tied to the asset inventory
- Patch test/staging procedure with malware scanning
- Authenticated-source and signature/hash validation for updates
- Patching without a tested baseline
- Updates loaded from unverified sources
- Uncontrolled external/vendor laptops on the control network
Isolate ICS networks from any untrusted networks, especially the Internet; lock down all unused ports and turn off all unused services. Allow real-time external connectivity only where there is a defined business or control requirement; use one-way optical separation (data diode) where one-way communication suffices, and a single restricted port if bidirectional communication is necessary.
- ICS-to-untrusted network isolation architecture
- Unused port/service hardening records
- Data-diode or single-restricted-port design for required external flows
- ICS devices directly reachable from the Internet
- Unused ports/services left open
Limit damage from perimeter breaches by segmenting networks into logical enclaves and restricting host-to-host communication paths so a compromised system cannot reach other enclaves. Where one-way transfer between zones is required, use approved removable media or optical separation rather than a live network connection.
- Logical enclave segmentation with restricted host-to-host paths
- Controlled one-way transfer mechanism between zones
- Flat control network without enclaving
- Direct corporate-to-control network connections
Protect credentials, especially highly privileged accounts: implement multi-factor authentication where possible, reduce privileges to least necessary, enforce secure password policy (length over complexity), ensure unique credentials for all accounts including system/non-interactive, and rotate at least every 90 days. Require separate credentials and trust stores for corporate versus control-network zones and never share Active Directory or other trust stores between them.
- MFA on control-system and privileged accounts
- Least-privilege account model
- Separate corporate vs control-network credential stores
- Shared admin passwords across the environment
- Shared trust stores between corporate and control zones
Remove obscure access vectors and back doors, especially modems; limit any remaining access. Where possible implement monitoring-only access enforced by data diodes (not software-enforced read-only); prohibit persistent vendor connections; require remote access to be operator-controlled, time-limited and procedurally similar to lock-out/tag-out; use the same paths for vendor and employee connections; and use two-factor authentication.
- Inventory and removal of back-door/modem access
- Operator-controlled, time-limited remote-access procedure
- Two-factor authentication on remote access; no persistent vendor tunnels
- Persistent vendor remote connections
- Modems or hidden remote-access paths
Actively monitor for adversarial penetration in five key places (IP traffic on ICS boundaries; IP traffic within the control network; host-based detection; login analysis for stolen-credential use; account/user-administration actions) and maintain a prepared response plan (disconnect, scoped malware search, disable affected accounts, isolate systems, full password reset, escalation) and a restoration plan including gold disks to restore systems to known-good states.
- Monitoring coverage across the five key ICS locations
- ICS/OT incident response plan with escalation triggers
- Restoration plan with known-good gold images
- No monitoring of the control network interior
- No OT-specific incident response or restoration plan
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the CISA Industrial Control Systems (ICS) Security Guidance framework page.