Cybersecurity GRC 16 items
OT/ICS Security Assessment (IEC 62443)
Assesses operational technology and industrial control system security using IEC 62443 and NIST SP 800-82, covering zones and conduits, remote access, patching, and safety.
IEC 62443NIST 800-82NIST 800-53
Free PDF · enter your email to download.
Asset Inventory & Zones
- Is a complete inventory of OT/ICS assets (PLCs, RTUs, HMIs, historians) maintained? *
- Are zones and conduits defined with documented security levels (SL-T)? *
- Is a risk assessment performed for each zone and conduit? *
- Are OT protocols and data flows documented?
Network Segmentation
- Is the OT network segmented from the IT/enterprise network (e.g., Purdue model)? *
- Is a DMZ used for data exchange between IT and OT (no direct IT-to-OT flows)? *
- Are conduits between zones enforced with firewalls or data diodes? *
- Is wireless access to OT networks controlled and monitored?
Access & Remote Connectivity
- Is remote vendor/maintenance access brokered, MFA-protected, and time-limited? *
- Are unique accounts used (no shared operator logins) where technically feasible? *
- Are removable media controls enforced for engineering workstations? *
- Are default credentials on OT devices changed where supported? *
Patching, Monitoring & Safety
- Is there a risk-based patch and change management process for OT that considers safety and uptime? *
- Is passive OT network monitoring deployed to detect anomalies without disruption? *
- Are safety instrumented systems (SIS) isolated from the control network? *
- Is there an OT-specific incident response and recovery plan?
Download the full OT/ICS Security Assessment (IEC 62443) checklist
Get it as a clean, printable PDF — free.
