ISO 27019
Evidence request list. 46 controls, 46 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Access Control
Define access control rules specific to control rooms, engineering workstations, and remote access.
- OT access policy
- Engineering workstation ACLs
- Remote vendor access procedure
- Jump host configuration
- Shared operator accounts
- Vendor remote access always-on
- No jump host enforcement
Restrict, log, and review privileged access on HMIs, EMS, and engineering stations.
- Privileged account list
- Session recording
- Quarterly access reviews
- Break glass procedure
- Default admin accounts active
- No session recording on HMI
- Break glass never reviewed
Acquisition
Apply secure development principles to bespoke control logic and HMI applications.
- Coding standards
- Peer review records
- Test environment evidence
- HMI design reviews
- No coding standards for ladder logic
- Test on production
- No peer review
Asset Management
Maintain a complete inventory of process control, SCADA, RTU, IED, and field assets.
- OT asset register
- Network diagrams Purdue model
- RTU/IED inventory
- Firmware version list
- Field devices missing
- Firmware versions stale
- Spare devices unrecorded
Classify process data, telemetry, control commands, and market sensitive data.
- Classification scheme
- Handling rules for telemetry
- Market data labels
- SCADA tag classification
- Telemetry treated as public
- No labels on historian data
- Operator screens not classified
Communications
Segmentation between IT, DMZ, and OT zones following Purdue or equivalent model.
- Network architecture diagram
- Firewall rule sets
- Zone-conduit register
- DMZ design
- Flat OT network
- No DMZ between IT and OT
- Engineering laptops dual-homed
Separate process control, safety, corporate, and external partner networks.
- VLAN list
- Inter-zone firewall ACLs
- Safety system isolation evidence
- Partner connection register
- Safety on shared VLAN
- Partner VPN reaches OT
- No zone documentation
Compliance
Identify and meet sector regulations such as NIS2, NERC CIP, or national equivalents.
- Regulatory register
- Mapping to controls
- Audit reports
- Regulator correspondence
- Register stale
- No mapping to ISO
- Findings unclosed
Continuity
Continuity arrangements ensuring continued energy supply during disruption.
- BCP for control room
- Black start procedures
- Manual operations playbook
- Resilience exercise results
- No manual fallback
- Black start untested
- Single control room
ISO 27019: Access Management
Physical and logical access controls. Control from ISO 27019 framework, domain: ISO 27019: Access Management.
- Electronic security perimeter diagram
- Remote access procedure
- Personnel risk assessment
- Access revocation log
- Perimeter not enforced at field sites
- Remote access without jump host
- Revocation delayed for contractors
Personnel risk assessment. Control from ISO 27019 framework, domain: ISO 27019: Access Management.
- Electronic security perimeter diagram
- Remote access procedure
- Personnel risk assessment
- Access revocation log
- Perimeter not enforced at field sites
- Remote access without jump host
- Revocation delayed for contractors
Electronic access perimeter management. Control from ISO 27019 framework, domain: ISO 27019: Access Management.
- Electronic security perimeter diagram
- Remote access procedure
- Personnel risk assessment
- Access revocation log
- Perimeter not enforced at field sites
- Remote access without jump host
- Revocation delayed for contractors
Interactive remote access security. Control from ISO 27019 framework, domain: ISO 27019: Access Management.
- Electronic security perimeter diagram
- Remote access procedure
- Personnel risk assessment
- Access revocation log
- Perimeter not enforced at field sites
- Remote access without jump host
- Revocation delayed for contractors
Revocation of access procedures. Control from ISO 27019 framework, domain: ISO 27019: Access Management.
- Electronic security perimeter diagram
- Remote access procedure
- Personnel risk assessment
- Access revocation log
- Perimeter not enforced at field sites
- Remote access without jump host
- Revocation delayed for contractors
ISO 27019: Asset Identification & Governance
Critical asset identification and inventory. Control from ISO 27019 framework, domain: ISO 27019: Asset Identification & Governance.
- Critical asset register
- OT security policy
- Categorization matrix
- OT roles and responsibilities
- OT inventory incomplete
- Categorization rationale missing
- Policy not enforced in OT
System security categorization. Control from ISO 27019 framework, domain: ISO 27019: Asset Identification & Governance.
- Critical asset register
- OT security policy
- Categorization matrix
- OT roles and responsibilities
- OT inventory incomplete
- Categorization rationale missing
- Policy not enforced in OT
Security governance structure. Control from ISO 27019 framework, domain: ISO 27019: Asset Identification & Governance.
- Critical asset register
- OT security policy
- Categorization matrix
- OT roles and responsibilities
- OT inventory incomplete
- Categorization rationale missing
- Policy not enforced in OT
Roles and responsibilities for critical systems. Control from ISO 27019 framework, domain: ISO 27019: Asset Identification & Governance.
- Critical asset register
- OT security policy
- Categorization matrix
- OT roles and responsibilities
- OT inventory incomplete
- Categorization rationale missing
- Policy not enforced in OT
Security policy for operational technology. Control from ISO 27019 framework, domain: ISO 27019: Asset Identification & Governance.
- Critical asset register
- OT security policy
- Categorization matrix
- OT roles and responsibilities
- OT inventory incomplete
- Categorization rationale missing
- Policy not enforced in OT
ISO 27019: Incident Response & Recovery
Incident response plan for operational disruptions. Control from ISO 27019 framework, domain: ISO 27019: Incident Response & Recovery.
- OT incident response plan
- Recovery time objectives
- Regulator reporting template
- Drill report
- IR plan not OT-specific
- RTO not validated by drill
- Reporting templates outdated
Recovery plan for critical systems. Control from ISO 27019 framework, domain: ISO 27019: Incident Response & Recovery.
- OT incident response plan
- Recovery time objectives
- Regulator reporting template
- Drill report
- IR plan not OT-specific
- RTO not validated by drill
- Reporting templates outdated
Reporting obligations to authorities. Control from ISO 27019 framework, domain: ISO 27019: Incident Response & Recovery.
- OT incident response plan
- Recovery time objectives
- Regulator reporting template
- Drill report
- IR plan not OT-specific
- RTO not validated by drill
- Reporting templates outdated
Coordination with sector-specific agencies. Control from ISO 27019 framework, domain: ISO 27019: Incident Response & Recovery.
- OT incident response plan
- Recovery time objectives
- Regulator reporting template
- Drill report
- IR plan not OT-specific
- RTO not validated by drill
- Reporting templates outdated
Exercises and drills for OT incidents. Control from ISO 27019 framework, domain: ISO 27019: Incident Response & Recovery.
- OT incident response plan
- Recovery time objectives
- Regulator reporting template
- Drill report
- IR plan not OT-specific
- RTO not validated by drill
- Reporting templates outdated
ISO 27019: Supply Chain & Configuration
Supply chain risk management for critical components. Control from ISO 27019 framework, domain: ISO 27019: Supply Chain & Configuration.
- Supplier risk register
- OT configuration baseline
- Change advisory minutes
- Vulnerability assessment report
- Supplier risk not differentiated for OT
- Configuration drift undetected
- Change board lacks OT representation
Configuration management for OT systems. Control from ISO 27019 framework, domain: ISO 27019: Supply Chain & Configuration.
- Supplier risk register
- OT configuration baseline
- Change advisory minutes
- Vulnerability assessment report
- Supplier risk not differentiated for OT
- Configuration drift undetected
- Change board lacks OT representation
Change management procedures. Control from ISO 27019 framework, domain: ISO 27019: Supply Chain & Configuration.
- Supplier risk register
- OT configuration baseline
- Change advisory minutes
- Vulnerability assessment report
- Supplier risk not differentiated for OT
- Configuration drift undetected
- Change board lacks OT representation
Vulnerability assessment for critical systems. Control from ISO 27019 framework, domain: ISO 27019: Supply Chain & Configuration.
- Supplier risk register
- OT configuration baseline
- Change advisory minutes
- Vulnerability assessment report
- Supplier risk not differentiated for OT
- Configuration drift undetected
- Change board lacks OT representation
ISO 27019: Systems Security
Security patch management for OT. Control from ISO 27019 framework, domain: ISO 27019: Systems Security.
- OT patch management plan
- OT malware controls register
- Network monitoring sensors
- Hardening baseline
- Patches delayed for control system fear
- AV not validated for OT
- Ports/services not baselined
Malware prevention for operational systems. Control from ISO 27019 framework, domain: ISO 27019: Systems Security.
- OT patch management plan
- OT malware controls register
- Network monitoring sensors
- Hardening baseline
- Patches delayed for control system fear
- AV not validated for OT
- Ports/services not baselined
Network security monitoring. Control from ISO 27019 framework, domain: ISO 27019: Systems Security.
- OT patch management plan
- OT malware controls register
- Network monitoring sensors
- Hardening baseline
- Patches delayed for control system fear
- AV not validated for OT
- Ports/services not baselined
System security hardening. Control from ISO 27019 framework, domain: ISO 27019: Systems Security.
- OT patch management plan
- OT malware controls register
- Network monitoring sensors
- Hardening baseline
- Patches delayed for control system fear
- AV not validated for OT
- Ports/services not baselined
Ports and services management. Control from ISO 27019 framework, domain: ISO 27019: Systems Security.
- OT patch management plan
- OT malware controls register
- Network monitoring sensors
- Hardening baseline
- Patches delayed for control system fear
- AV not validated for OT
- Ports/services not baselined
Incident
Incident response covering cyber events impacting generation, transmission, or distribution.
- IR plan with OT scenarios
- Playbooks for SCADA compromise
- Tabletop exercise records
- Regulator notification log
- IR plan IT only
- No OT scenarios tested
- Regulator timing unclear
Operations
Formal change management for SCADA, EMS, RTU firmware, and protection settings.
- Change tickets
- CAB minutes
- Protection setting change log
- Rollback plans
- Emergency changes never reviewed
- No rollback for firmware
- Protection changes informal
Anti-malware for OT systems where supported, with compensating controls where not.
- AV coverage report
- Vendor-approved AV list
- Whitelisting on HMIs
- Compensating control register
- AV unsupported by vendor
- No whitelisting
- Definitions stale on isolated systems
Backup SCADA configurations, PLC programs, protection settings, and historian data.
- Backup schedule
- Restore test logs
- Offsite backup proof
- Configuration repository
- PLC programs not backed up
- No restore tests
- Backups stored on same network
Capture operator actions, alarms, control commands, and system events.
- SCADA event logs
- Operator action audit
- Alarm history
- SIEM integration evidence
- Logs local only
- No SIEM forwarding
- Operator actions not attributable
Identify, assess, and remediate vulnerabilities in control systems with safety considerations.
- Passive scan reports
- Vendor advisories tracker
- Patch risk assessments
- Maintenance window schedule
- Active scanning crashes devices
- Patches deferred indefinitely
- No advisory tracking
Organizational
Define and assign information security roles covering process control, SCADA, and energy operations staff.
- OT/IT role matrix
- RACI for control systems
- Job descriptions for SCADA engineers
- Security officer appointment letter
- OT roles not separated from IT
- Vendor engineer access not documented
- No process control security lead
Integrate security into engineering, commissioning, and decommissioning projects for energy systems.
- Project security plans
- Commissioning checklists
- FAT/SAT security tests
- Decommissioning records
- Legacy projects exempted
- No security gate at commissioning
- Decommissioning leaves credentials active
People
Background screening for staff and contractors accessing process control systems.
- Screening policy
- Background check records
- Contractor vetting attestations
- Re-screening schedule
- Contractors not screened
- No re-screening for long-tenured engineers
- Vendor field staff exempt
Physical
Physical perimeters around substations, generation plants, control rooms, and unmanned sites.
- Site security plans
- Perimeter inspection logs
- CCTV coverage maps
- Intrusion alarms
- Unmanned substations unmonitored
- CCTV blind spots
- No intrusion alarms on rural sites
Secure maintenance of OT equipment including media handling and tool control.
- Maintenance procedures
- Tool registers
- Removable media policy
- Vendor maintenance logs
- USB sticks shared across sites
- No media scanning
- Vendor laptops unchecked
Sector Specific
Coordinate cyber security with functional safety and physical safety processes.
- Joint safety-security committee minutes
- HAZOP with cyber inputs
- SIS isolation evidence
- Combined risk register
- Safety and security siloed
- HAZOP excludes cyber
- SIS shares network
Supplier
Security requirements for OT vendors, EPC contractors, and maintenance providers.
- Supplier security schedules
- EPC contract clauses
- Vendor risk assessments
- Right-to-audit clauses
- Legacy vendors unscored
- No right-to-audit
- EPC contracts silent on security
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 27019 framework page.