Skip to content

Evidence request lists

ISO 27019

Evidence request list. 46 controls, 46 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Access Control

ISO27019-9.1.1
Access Control Policy for Control Systems

Define access control rules specific to control rooms, engineering workstations, and remote access.

Artefacts an auditor will ask for
  • OT access policy
  • Engineering workstation ACLs
  • Remote vendor access procedure
  • Jump host configuration
Where this commonly fails
  • Shared operator accounts
  • Vendor remote access always-on
  • No jump host enforcement
ISO27019-9.2.3
Privileged Access in Control Environments

Restrict, log, and review privileged access on HMIs, EMS, and engineering stations.

Artefacts an auditor will ask for
  • Privileged account list
  • Session recording
  • Quarterly access reviews
  • Break glass procedure
Where this commonly fails
  • Default admin accounts active
  • No session recording on HMI
  • Break glass never reviewed

Acquisition

ISO27019-14.2.1
Secure Development of Control Applications

Apply secure development principles to bespoke control logic and HMI applications.

Artefacts an auditor will ask for
  • Coding standards
  • Peer review records
  • Test environment evidence
  • HMI design reviews
Where this commonly fails
  • No coding standards for ladder logic
  • Test on production
  • No peer review

Asset Management

ISO27019-8.1.1
Inventory of Process Control Assets

Maintain a complete inventory of process control, SCADA, RTU, IED, and field assets.

Artefacts an auditor will ask for
  • OT asset register
  • Network diagrams Purdue model
  • RTU/IED inventory
  • Firmware version list
Where this commonly fails
  • Field devices missing
  • Firmware versions stale
  • Spare devices unrecorded
ISO27019-8.2.1
Classification of Energy Sector Information

Classify process data, telemetry, control commands, and market sensitive data.

Artefacts an auditor will ask for
  • Classification scheme
  • Handling rules for telemetry
  • Market data labels
  • SCADA tag classification
Where this commonly fails
  • Telemetry treated as public
  • No labels on historian data
  • Operator screens not classified

Communications

ISO27019-13.1.1
Network Security for Energy Operations

Segmentation between IT, DMZ, and OT zones following Purdue or equivalent model.

Artefacts an auditor will ask for
  • Network architecture diagram
  • Firewall rule sets
  • Zone-conduit register
  • DMZ design
Where this commonly fails
  • Flat OT network
  • No DMZ between IT and OT
  • Engineering laptops dual-homed
ISO27019-13.1.3
Segregation of Networks

Separate process control, safety, corporate, and external partner networks.

Artefacts an auditor will ask for
  • VLAN list
  • Inter-zone firewall ACLs
  • Safety system isolation evidence
  • Partner connection register
Where this commonly fails
  • Safety on shared VLAN
  • Partner VPN reaches OT
  • No zone documentation

Compliance

ISO27019-18.1.1
Compliance with Energy Sector Regulations

Identify and meet sector regulations such as NIS2, NERC CIP, or national equivalents.

Artefacts an auditor will ask for
  • Regulatory register
  • Mapping to controls
  • Audit reports
  • Regulator correspondence
Where this commonly fails
  • Register stale
  • No mapping to ISO
  • Findings unclosed

Continuity

ISO27019-17.1.2
Business Continuity for Energy Supply

Continuity arrangements ensuring continued energy supply during disruption.

Artefacts an auditor will ask for
  • BCP for control room
  • Black start procedures
  • Manual operations playbook
  • Resilience exercise results
Where this commonly fails
  • No manual fallback
  • Black start untested
  • Single control room

ISO 27019: Access Management

ISO27019-06
Physical and logical access controls

Physical and logical access controls. Control from ISO 27019 framework, domain: ISO 27019: Access Management.

Artefacts an auditor will ask for
  • Electronic security perimeter diagram
  • Remote access procedure
  • Personnel risk assessment
  • Access revocation log
Where this commonly fails
  • Perimeter not enforced at field sites
  • Remote access without jump host
  • Revocation delayed for contractors
ISO27019-07
Personnel risk assessment

Personnel risk assessment. Control from ISO 27019 framework, domain: ISO 27019: Access Management.

Artefacts an auditor will ask for
  • Electronic security perimeter diagram
  • Remote access procedure
  • Personnel risk assessment
  • Access revocation log
Where this commonly fails
  • Perimeter not enforced at field sites
  • Remote access without jump host
  • Revocation delayed for contractors
ISO27019-08
Electronic access perimeter management

Electronic access perimeter management. Control from ISO 27019 framework, domain: ISO 27019: Access Management.

Artefacts an auditor will ask for
  • Electronic security perimeter diagram
  • Remote access procedure
  • Personnel risk assessment
  • Access revocation log
Where this commonly fails
  • Perimeter not enforced at field sites
  • Remote access without jump host
  • Revocation delayed for contractors
ISO27019-09
Interactive remote access security

Interactive remote access security. Control from ISO 27019 framework, domain: ISO 27019: Access Management.

Artefacts an auditor will ask for
  • Electronic security perimeter diagram
  • Remote access procedure
  • Personnel risk assessment
  • Access revocation log
Where this commonly fails
  • Perimeter not enforced at field sites
  • Remote access without jump host
  • Revocation delayed for contractors
ISO27019-10
Revocation of access procedures

Revocation of access procedures. Control from ISO 27019 framework, domain: ISO 27019: Access Management.

Artefacts an auditor will ask for
  • Electronic security perimeter diagram
  • Remote access procedure
  • Personnel risk assessment
  • Access revocation log
Where this commonly fails
  • Perimeter not enforced at field sites
  • Remote access without jump host
  • Revocation delayed for contractors

ISO 27019: Asset Identification & Governance

ISO27019-01
Critical asset identification and inventory

Critical asset identification and inventory. Control from ISO 27019 framework, domain: ISO 27019: Asset Identification & Governance.

Artefacts an auditor will ask for
  • Critical asset register
  • OT security policy
  • Categorization matrix
  • OT roles and responsibilities
Where this commonly fails
  • OT inventory incomplete
  • Categorization rationale missing
  • Policy not enforced in OT
ISO27019-02
System security categorization

System security categorization. Control from ISO 27019 framework, domain: ISO 27019: Asset Identification & Governance.

Artefacts an auditor will ask for
  • Critical asset register
  • OT security policy
  • Categorization matrix
  • OT roles and responsibilities
Where this commonly fails
  • OT inventory incomplete
  • Categorization rationale missing
  • Policy not enforced in OT
ISO27019-03
Security governance structure

Security governance structure. Control from ISO 27019 framework, domain: ISO 27019: Asset Identification & Governance.

Artefacts an auditor will ask for
  • Critical asset register
  • OT security policy
  • Categorization matrix
  • OT roles and responsibilities
Where this commonly fails
  • OT inventory incomplete
  • Categorization rationale missing
  • Policy not enforced in OT
ISO27019-04
Roles and responsibilities for critical systems

Roles and responsibilities for critical systems. Control from ISO 27019 framework, domain: ISO 27019: Asset Identification & Governance.

Artefacts an auditor will ask for
  • Critical asset register
  • OT security policy
  • Categorization matrix
  • OT roles and responsibilities
Where this commonly fails
  • OT inventory incomplete
  • Categorization rationale missing
  • Policy not enforced in OT
ISO27019-05
Security policy for operational technology

Security policy for operational technology. Control from ISO 27019 framework, domain: ISO 27019: Asset Identification & Governance.

Artefacts an auditor will ask for
  • Critical asset register
  • OT security policy
  • Categorization matrix
  • OT roles and responsibilities
Where this commonly fails
  • OT inventory incomplete
  • Categorization rationale missing
  • Policy not enforced in OT

ISO 27019: Incident Response & Recovery

ISO27019-16
Incident response plan for operational disruptions

Incident response plan for operational disruptions. Control from ISO 27019 framework, domain: ISO 27019: Incident Response & Recovery.

Artefacts an auditor will ask for
  • OT incident response plan
  • Recovery time objectives
  • Regulator reporting template
  • Drill report
Where this commonly fails
  • IR plan not OT-specific
  • RTO not validated by drill
  • Reporting templates outdated
ISO27019-17
Recovery plan for critical systems

Recovery plan for critical systems. Control from ISO 27019 framework, domain: ISO 27019: Incident Response & Recovery.

Artefacts an auditor will ask for
  • OT incident response plan
  • Recovery time objectives
  • Regulator reporting template
  • Drill report
Where this commonly fails
  • IR plan not OT-specific
  • RTO not validated by drill
  • Reporting templates outdated
ISO27019-18
Reporting obligations to authorities

Reporting obligations to authorities. Control from ISO 27019 framework, domain: ISO 27019: Incident Response & Recovery.

Artefacts an auditor will ask for
  • OT incident response plan
  • Recovery time objectives
  • Regulator reporting template
  • Drill report
Where this commonly fails
  • IR plan not OT-specific
  • RTO not validated by drill
  • Reporting templates outdated
ISO27019-19
Coordination with sector-specific agencies

Coordination with sector-specific agencies. Control from ISO 27019 framework, domain: ISO 27019: Incident Response & Recovery.

Artefacts an auditor will ask for
  • OT incident response plan
  • Recovery time objectives
  • Regulator reporting template
  • Drill report
Where this commonly fails
  • IR plan not OT-specific
  • RTO not validated by drill
  • Reporting templates outdated
ISO27019-20
Exercises and drills for OT incidents

Exercises and drills for OT incidents. Control from ISO 27019 framework, domain: ISO 27019: Incident Response & Recovery.

Artefacts an auditor will ask for
  • OT incident response plan
  • Recovery time objectives
  • Regulator reporting template
  • Drill report
Where this commonly fails
  • IR plan not OT-specific
  • RTO not validated by drill
  • Reporting templates outdated

ISO 27019: Supply Chain & Configuration

ISO27019-21
Supply chain risk management for critical components

Supply chain risk management for critical components. Control from ISO 27019 framework, domain: ISO 27019: Supply Chain & Configuration.

Artefacts an auditor will ask for
  • Supplier risk register
  • OT configuration baseline
  • Change advisory minutes
  • Vulnerability assessment report
Where this commonly fails
  • Supplier risk not differentiated for OT
  • Configuration drift undetected
  • Change board lacks OT representation
ISO27019-22
Configuration management for OT systems

Configuration management for OT systems. Control from ISO 27019 framework, domain: ISO 27019: Supply Chain & Configuration.

Artefacts an auditor will ask for
  • Supplier risk register
  • OT configuration baseline
  • Change advisory minutes
  • Vulnerability assessment report
Where this commonly fails
  • Supplier risk not differentiated for OT
  • Configuration drift undetected
  • Change board lacks OT representation
ISO27019-23
Change management procedures

Change management procedures. Control from ISO 27019 framework, domain: ISO 27019: Supply Chain & Configuration.

Artefacts an auditor will ask for
  • Supplier risk register
  • OT configuration baseline
  • Change advisory minutes
  • Vulnerability assessment report
Where this commonly fails
  • Supplier risk not differentiated for OT
  • Configuration drift undetected
  • Change board lacks OT representation
ISO27019-24
Vulnerability assessment for critical systems

Vulnerability assessment for critical systems. Control from ISO 27019 framework, domain: ISO 27019: Supply Chain & Configuration.

Artefacts an auditor will ask for
  • Supplier risk register
  • OT configuration baseline
  • Change advisory minutes
  • Vulnerability assessment report
Where this commonly fails
  • Supplier risk not differentiated for OT
  • Configuration drift undetected
  • Change board lacks OT representation

ISO 27019: Systems Security

ISO27019-11
Security patch management for OT

Security patch management for OT. Control from ISO 27019 framework, domain: ISO 27019: Systems Security.

Artefacts an auditor will ask for
  • OT patch management plan
  • OT malware controls register
  • Network monitoring sensors
  • Hardening baseline
Where this commonly fails
  • Patches delayed for control system fear
  • AV not validated for OT
  • Ports/services not baselined
ISO27019-12
Malware prevention for operational systems

Malware prevention for operational systems. Control from ISO 27019 framework, domain: ISO 27019: Systems Security.

Artefacts an auditor will ask for
  • OT patch management plan
  • OT malware controls register
  • Network monitoring sensors
  • Hardening baseline
Where this commonly fails
  • Patches delayed for control system fear
  • AV not validated for OT
  • Ports/services not baselined
ISO27019-13
Network security monitoring

Network security monitoring. Control from ISO 27019 framework, domain: ISO 27019: Systems Security.

Artefacts an auditor will ask for
  • OT patch management plan
  • OT malware controls register
  • Network monitoring sensors
  • Hardening baseline
Where this commonly fails
  • Patches delayed for control system fear
  • AV not validated for OT
  • Ports/services not baselined
ISO27019-14
System security hardening

System security hardening. Control from ISO 27019 framework, domain: ISO 27019: Systems Security.

Artefacts an auditor will ask for
  • OT patch management plan
  • OT malware controls register
  • Network monitoring sensors
  • Hardening baseline
Where this commonly fails
  • Patches delayed for control system fear
  • AV not validated for OT
  • Ports/services not baselined
ISO27019-15
Ports and services management

Ports and services management. Control from ISO 27019 framework, domain: ISO 27019: Systems Security.

Artefacts an auditor will ask for
  • OT patch management plan
  • OT malware controls register
  • Network monitoring sensors
  • Hardening baseline
Where this commonly fails
  • Patches delayed for control system fear
  • AV not validated for OT
  • Ports/services not baselined

Incident

ISO27019-16.1.1
Incident Management for Energy Operations

Incident response covering cyber events impacting generation, transmission, or distribution.

Artefacts an auditor will ask for
  • IR plan with OT scenarios
  • Playbooks for SCADA compromise
  • Tabletop exercise records
  • Regulator notification log
Where this commonly fails
  • IR plan IT only
  • No OT scenarios tested
  • Regulator timing unclear

Operations

ISO27019-12.1.2
Change Management for Control Systems

Formal change management for SCADA, EMS, RTU firmware, and protection settings.

Artefacts an auditor will ask for
  • Change tickets
  • CAB minutes
  • Protection setting change log
  • Rollback plans
Where this commonly fails
  • Emergency changes never reviewed
  • No rollback for firmware
  • Protection changes informal
ISO27019-12.2.1
Malware Protection in OT

Anti-malware for OT systems where supported, with compensating controls where not.

Artefacts an auditor will ask for
  • AV coverage report
  • Vendor-approved AV list
  • Whitelisting on HMIs
  • Compensating control register
Where this commonly fails
  • AV unsupported by vendor
  • No whitelisting
  • Definitions stale on isolated systems
ISO27019-12.3.1
Backup of Control System Configurations

Backup SCADA configurations, PLC programs, protection settings, and historian data.

Artefacts an auditor will ask for
  • Backup schedule
  • Restore test logs
  • Offsite backup proof
  • Configuration repository
Where this commonly fails
  • PLC programs not backed up
  • No restore tests
  • Backups stored on same network
ISO27019-12.4.1
Event Logging in Control Systems

Capture operator actions, alarms, control commands, and system events.

Artefacts an auditor will ask for
  • SCADA event logs
  • Operator action audit
  • Alarm history
  • SIEM integration evidence
Where this commonly fails
  • Logs local only
  • No SIEM forwarding
  • Operator actions not attributable
ISO27019-12.6.1
Vulnerability Management for OT

Identify, assess, and remediate vulnerabilities in control systems with safety considerations.

Artefacts an auditor will ask for
  • Passive scan reports
  • Vendor advisories tracker
  • Patch risk assessments
  • Maintenance window schedule
Where this commonly fails
  • Active scanning crashes devices
  • Patches deferred indefinitely
  • No advisory tracking

Organizational

ISO27019-6.1.1
Information Security Roles for Energy Operations

Define and assign information security roles covering process control, SCADA, and energy operations staff.

Artefacts an auditor will ask for
  • OT/IT role matrix
  • RACI for control systems
  • Job descriptions for SCADA engineers
  • Security officer appointment letter
Where this commonly fails
  • OT roles not separated from IT
  • Vendor engineer access not documented
  • No process control security lead
ISO27019-6.1.5
Information Security in Project Management for Energy

Integrate security into engineering, commissioning, and decommissioning projects for energy systems.

Artefacts an auditor will ask for
  • Project security plans
  • Commissioning checklists
  • FAT/SAT security tests
  • Decommissioning records
Where this commonly fails
  • Legacy projects exempted
  • No security gate at commissioning
  • Decommissioning leaves credentials active

People

ISO27019-7.1.1
Screening of Personnel with OT Access

Background screening for staff and contractors accessing process control systems.

Artefacts an auditor will ask for
  • Screening policy
  • Background check records
  • Contractor vetting attestations
  • Re-screening schedule
Where this commonly fails
  • Contractors not screened
  • No re-screening for long-tenured engineers
  • Vendor field staff exempt

Physical

ISO27019-11.1.1
Physical Security for Substations and Plants

Physical perimeters around substations, generation plants, control rooms, and unmanned sites.

Artefacts an auditor will ask for
  • Site security plans
  • Perimeter inspection logs
  • CCTV coverage maps
  • Intrusion alarms
Where this commonly fails
  • Unmanned substations unmonitored
  • CCTV blind spots
  • No intrusion alarms on rural sites
ISO27019-11.2.4
Maintenance of Process Control Equipment

Secure maintenance of OT equipment including media handling and tool control.

Artefacts an auditor will ask for
  • Maintenance procedures
  • Tool registers
  • Removable media policy
  • Vendor maintenance logs
Where this commonly fails
  • USB sticks shared across sites
  • No media scanning
  • Vendor laptops unchecked

Sector Specific

ISO27019-ENR.1
Safety and Security Integration

Coordinate cyber security with functional safety and physical safety processes.

Artefacts an auditor will ask for
  • Joint safety-security committee minutes
  • HAZOP with cyber inputs
  • SIS isolation evidence
  • Combined risk register
Where this commonly fails
  • Safety and security siloed
  • HAZOP excludes cyber
  • SIS shares network

Supplier

ISO27019-15.1.1
Supplier Relationships in Energy

Security requirements for OT vendors, EPC contractors, and maintenance providers.

Artefacts an auditor will ask for
  • Supplier security schedules
  • EPC contract clauses
  • Vendor risk assessments
  • Right-to-audit clauses
Where this commonly fails
  • Legacy vendors unscored
  • No right-to-audit
  • EPC contracts silent on security
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 27019 framework page.