Sekit CSF · Familia
OT/ICS Security
15 controles en 5 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0427IR for ICS5 mapeosIncident response procedures specific to operational technology environments are formally definedRCF-0421Network segmentation (ICS)4 mapeosIndustrial control systems are formally required to be separated from corporate IT networksRCF-0418OT asset inventory3 mapeosAll operational technology and industrial control system assets are formally required to be identified and recordedRCF-0424Patch/compensating controls (ICS)5 mapeosA formal approach manages security vulnerabilities in OT systems where traditional patching is not possibleRCF-0430Safety alignment4 mapeosCybersecurity requirements are formally aligned with operational safety and physical process requirements
Proceso
RCF-0428IR for ICS5 mapeosICS-specific incident response procedures are consistently followed when operational systems are affectedRCF-0422Network segmentation (ICS)4 mapeosICS network boundaries are consistently maintained and cross-boundary traffic is strictly controlledRCF-0419OT asset inventory3 mapeosOT and ICS assets are consistently inventoried and changes to the OT environment are trackedRCF-0425Patch/compensating controls (ICS)4 mapeosOT vulnerabilities are consistently assessed and compensating controls are applied where patching is not feasibleRCF-0431Safety alignment3 mapeosSecurity decisions in OT environments consistently take into account the impact on operational safety
Técnica
RCF-0429IR for ICS5 mapeosTechnical tools support safe detection and response to incidents in OT environments without disrupting operationsRCF-0423Network segmentation (ICS)5 mapeosTechnical controls enforce network separation between ICS and IT environments through firewalls and unidirectional gatewaysRCF-0420OT asset inventory4 mapeosTechnical tools passively discover and maintain an inventory of OT and ICS devices without disrupting operationsRCF-0426Patch/compensating controls (ICS)6 mapeosTechnical compensating controls such as network monitoring and application whitelisting protect unpatched OT systemsRCF-0432Safety alignment4 mapeosTechnical security controls are designed and validated to avoid interfering with safety-critical operational processes
Esta familia en ISO/IEC 27001:2022
Cada elemento de marco al que mapean los controles de la familia, primero los más conectados; agrupado por familia del Sekit CSF, nunca por el índice del propio marco.
Esta familia en NIST CSF 2.0
Esta familia en Cyber Essentials
Pregúntale a Sekura: «¿Qué evidencia demuestra OT/ICS Security?»
También vía MCP, gratis con cuenta