Skip to content

Evidence request lists

CISA Industrial Control Systems (ICS) Security Guidance

Evidence request list. 16 controls, 16 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

CISA ICS: Defense-in-Depth Recommended Practice

CISA-ICS-DID-21
Risk Management for ICS

Integrate ICS cybersecurity risk into a multitier (organisation, mission/business, system) risk-management approach tailored to the operational-technology context and its safety, reliability and availability priorities.

Artefacts an auditor will ask for
  • ICS cyber risk-management approach integrated across organisation/mission/system tiers
  • Risk register reflecting OT safety and availability priorities
Where this commonly fails
  • IT risk process applied to OT without tailoring
  • No OT representation in enterprise risk management
CISA-ICS-DID-22
Asset Inventory and Risk Characterization

Maintain an inventory of ICS assets, categorise asset criticality, identify security risks, determine potential impact, tailor and implement security controls, and monitor and adjust. The inventory is the basis for patching, segmentation and risk characterisation.

Artefacts an auditor will ask for
  • Current ICS/OT asset inventory with criticality categorisation
  • Risk characterisation and impact determination per asset class
  • Control-tailoring and monitor/adjust records
Where this commonly fails
  • Incomplete or stale OT asset inventory
  • Criticality not assessed
CISA-ICS-DID-23
Physical Security

Protect physical access to ICS assets, control centres, field devices, network equipment and cabling, recognising that physical access often defeats logical controls in OT environments.

Artefacts an auditor will ask for
  • Physical access controls for control centres and field/equipment locations
  • Monitoring of physical access to OT assets
Where this commonly fails
  • Unsecured field devices/cabinets
  • No physical access logging for control rooms
CISA-ICS-DID-24
ICS Network Architecture

Design ICS network architecture using defined zones, a demilitarised zone (DMZ) between the control network and the corporate/enterprise network, and VLAN segmentation to separate functions and contain compromise.

Artefacts an auditor will ask for
  • Zoned ICS network architecture diagram with an IT/OT DMZ
  • VLAN segmentation of control functions
Where this commonly fails
  • No DMZ between corporate and control networks
  • Unsegmented control LAN
CISA-ICS-DID-25
Security Architecture (Perimeter, Firewalls, Diodes, Access)

Implement layered security architecture: perimeter security, firewalls between zones, unidirectional gateways/diodes where appropriate, access and authentication controls, and restrictions on bring-your-own-device.

Artefacts an auditor will ask for
  • Firewall rulebase between corporate, DMZ and control zones
  • Unidirectional gateway/diode deployment where applicable
  • BYOD restriction policy for the control environment
Where this commonly fails
  • Permissive firewall rules into the control zone
  • Personal devices permitted on OT networks
CISA-ICS-DID-26
Host Security (Patch, Field Devices, Virtual Machines)

Harden ICS hosts through patch and vulnerability management, securing of field devices, and security of virtual machines used in the control environment.

Artefacts an auditor will ask for
  • Host hardening baselines for servers, workstations and field devices
  • Patch/vulnerability management for OT hosts and VMs
Where this commonly fails
  • Unhardened HMI/engineering hosts
  • Field devices excluded from vulnerability management
CISA-ICS-DID-27
Security Monitoring (IDS/IPS, Logging, SIEM)

Deploy security monitoring across the ICS: intrusion detection and prevention systems suited to OT protocols, security audit logging, and security incident and event monitoring (SIEM) to detect and correlate adversarial activity.

Artefacts an auditor will ask for
  • OT-aware IDS/IPS coverage
  • Security audit logging from ICS assets forwarded to monitoring
  • SIEM correlation and alerting for the control environment
Where this commonly fails
  • No monitoring of OT protocols
  • ICS logs not collected or reviewed
CISA-ICS-DID-28
Vendor Management and Supply Chain Security

Manage vendor and supply-chain security for ICS components, including integrator and maintenance-provider security, third-party access, and provenance of hardware/software/patches.

Artefacts an auditor will ask for
  • Vendor/integrator security requirements and assessments
  • Supply-chain provenance and patch-authenticity controls for ICS components
  • Control over third-party/maintenance access
Where this commonly fails
  • No security requirements on integrators/vendors
  • Unverified component or patch provenance
CISA-ICS-DID-29
The Human Element (Awareness and Training)

Address the human element through security awareness, role-based training for operators and engineers, and policies that reduce social-engineering and insider risk in the control environment.

Artefacts an auditor will ask for
  • Role-based ICS security awareness and training programme
  • Policies addressing social engineering and insider risk
Where this commonly fails
  • No OT-specific security training
  • Operators unaware of cyber threats

CISA ICS: Seven Steps to Effectively Defend ICS

CISA-ICS-7S-1
Implement Application Allowlisting (Whitelisting)

Deploy application allowlisting (AWL) to detect and prevent execution of malware uploaded by adversaries; static systems such as HMI computers and database servers are ideal candidates. Baseline and calibrate AWL deployments in cooperation with the control-system vendor.

Artefacts an auditor will ask for
  • Application allowlisting deployed on HMI/database/static hosts
  • AWL baseline and exception process agreed with the vendor
  • Alerts on blocked-execution events
Where this commonly fails
  • AWL absent on HMI/engineering hosts
  • Reliance on signature antivirus only
CISA-ICS-7S-2
Ensure Proper Configuration and Patch Management

Run a configuration/patch management program built on an accurate baseline and asset inventory, prioritising PC-architecture machines (HMI, database server, engineering workstation roles). Limit connection of external laptops, prefer known-good vendor laptops, and test updates on an isolated system with malware detection before operational deployment. Obtain updates from authenticated vendor sites and validate authenticity via digital signatures or out-of-band hashes.

Artefacts an auditor will ask for
  • ICS patch/configuration baseline tied to the asset inventory
  • Patch test/staging procedure with malware scanning
  • Authenticated-source and signature/hash validation for updates
Where this commonly fails
  • Patching without a tested baseline
  • Updates loaded from unverified sources
  • Uncontrolled external/vendor laptops on the control network
CISA-ICS-7S-3
Reduce Your Attack Surface Area

Isolate ICS networks from any untrusted networks, especially the Internet; lock down all unused ports and turn off all unused services. Allow real-time external connectivity only where there is a defined business or control requirement; use one-way optical separation (data diode) where one-way communication suffices, and a single restricted port if bidirectional communication is necessary.

Artefacts an auditor will ask for
  • ICS-to-untrusted network isolation architecture
  • Unused port/service hardening records
  • Data-diode or single-restricted-port design for required external flows
Where this commonly fails
  • ICS devices directly reachable from the Internet
  • Unused ports/services left open
CISA-ICS-7S-4
Build a Defendable Environment

Limit damage from perimeter breaches by segmenting networks into logical enclaves and restricting host-to-host communication paths so a compromised system cannot reach other enclaves. Where one-way transfer between zones is required, use approved removable media or optical separation rather than a live network connection.

Artefacts an auditor will ask for
  • Logical enclave segmentation with restricted host-to-host paths
  • Controlled one-way transfer mechanism between zones
Where this commonly fails
  • Flat control network without enclaving
  • Direct corporate-to-control network connections
CISA-ICS-7S-5
Manage Authentication

Protect credentials, especially highly privileged accounts: implement multi-factor authentication where possible, reduce privileges to least necessary, enforce secure password policy (length over complexity), ensure unique credentials for all accounts including system/non-interactive, and rotate at least every 90 days. Require separate credentials and trust stores for corporate versus control-network zones and never share Active Directory or other trust stores between them.

Artefacts an auditor will ask for
  • MFA on control-system and privileged accounts
  • Least-privilege account model
  • Separate corporate vs control-network credential stores
Where this commonly fails
  • Shared admin passwords across the environment
  • Shared trust stores between corporate and control zones
CISA-ICS-7S-6
Implement Secure Remote Access

Remove obscure access vectors and back doors, especially modems; limit any remaining access. Where possible implement monitoring-only access enforced by data diodes (not software-enforced read-only); prohibit persistent vendor connections; require remote access to be operator-controlled, time-limited and procedurally similar to lock-out/tag-out; use the same paths for vendor and employee connections; and use two-factor authentication.

Artefacts an auditor will ask for
  • Inventory and removal of back-door/modem access
  • Operator-controlled, time-limited remote-access procedure
  • Two-factor authentication on remote access; no persistent vendor tunnels
Where this commonly fails
  • Persistent vendor remote connections
  • Modems or hidden remote-access paths
CISA-ICS-7S-7
Monitor and Respond

Actively monitor for adversarial penetration in five key places (IP traffic on ICS boundaries; IP traffic within the control network; host-based detection; login analysis for stolen-credential use; account/user-administration actions) and maintain a prepared response plan (disconnect, scoped malware search, disable affected accounts, isolate systems, full password reset, escalation) and a restoration plan including gold disks to restore systems to known-good states.

Artefacts an auditor will ask for
  • Monitoring coverage across the five key ICS locations
  • ICS/OT incident response plan with escalation triggers
  • Restoration plan with known-good gold images
Where this commonly fails
  • No monitoring of the control network interior
  • No OT-specific incident response or restoration plan
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the CISA Industrial Control Systems (ICS) Security Guidance framework page.