simpl.
Cybersecurity GRC 16 items

OT/ICS Security Assessment (IEC 62443)

Assesses operational technology and industrial control system security using IEC 62443 and NIST SP 800-82, covering zones and conduits, remote access, patching, and safety.

IEC 62443NIST 800-82NIST 800-53

Free PDF · enter your email to download.

Asset Inventory & Zones

  • Is a complete inventory of OT/ICS assets (PLCs, RTUs, HMIs, historians) maintained? *
  • Are zones and conduits defined with documented security levels (SL-T)? *
  • Is a risk assessment performed for each zone and conduit? *
  • Are OT protocols and data flows documented?

Network Segmentation

  • Is the OT network segmented from the IT/enterprise network (e.g., Purdue model)? *
  • Is a DMZ used for data exchange between IT and OT (no direct IT-to-OT flows)? *
  • Are conduits between zones enforced with firewalls or data diodes? *
  • Is wireless access to OT networks controlled and monitored?

Access & Remote Connectivity

  • Is remote vendor/maintenance access brokered, MFA-protected, and time-limited? *
  • Are unique accounts used (no shared operator logins) where technically feasible? *
  • Are removable media controls enforced for engineering workstations? *
  • Are default credentials on OT devices changed where supported? *

Patching, Monitoring & Safety

  • Is there a risk-based patch and change management process for OT that considers safety and uptime? *
  • Is passive OT network monitoring deployed to detect anomalies without disruption? *
  • Are safety instrumented systems (SIS) isolated from the control network? *
  • Is there an OT-specific incident response and recovery plan?

Download the full OT/ICS Security Assessment (IEC 62443) checklist

Get it as a clean, printable PDF — free.