Sekit CSF · OT/ICS Security · Process
RCF-0428IR for ICS
ICS-specific incident response procedures are consistently followed when operational systems are affected
Mapping at a glance
RCF-0428IR for ICSOT/ICS Security · Process
A.5.24Information security incident management planning and preparationISO/IEC 27001:2022A.5.26Response to information security incidentsISO/IEC 27001:2022RS.MA-01Incident response plan executedNIST CSF 2.0RS.MA-02Incident reports triagedNIST CSF 2.0RS.MA-03Incidents categorized and prioritizedNIST CSF 2.0
RCF-0428 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.24Information security incident management planning and preparationsupportsPracticing the OT-specific response procedures so production, maintenance and IT each know their part is the tested readiness this control requires for operational technology incidents.A.5.26Response to information security incidentssupportsFollowing the OT-specific response procedures whenever an incident touches production systems contributes directly to this control's response requirement, but on its own only covers operational technology, not the organization-wide response this control asks for.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
RS.MA-01Incident response plan executedRS.MA-02Incident reports triagedRS.MA-03Incidents categorized and prioritized
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
OT/ICS security controls
The controls specific to industrial control systems: how their vulnerabilities and incidents are managed and how they align with the physical safety of processes.
From the Sekit evidence catalog
This topic through the other lenses
All OT/ICS Security controls
Ask Sekura: “What evidence proves RCF-0428?”
Also via MCP, free with account