ضوابط الأمن السيبراني للأنظمة التشغيلية (OTCC-1:2022)

الهيئة الوطنية للأمن السيبراني · 47 ضابطًا رئيسيًا · 120 فرعيًا

النسخة التفاعلية والتقييم ←

النص العربي الرسمي متاح في وثيقة الهيئة، ونقله الحرفي إلى المكتبة قيد التحقق البصري صفحة بصفحة، والمعروض حاليًا هو النص الإنجليزي الرسمي كما صدر. الرابط أدناه يفتح النسخة العربية الرسمية مباشرة من موقع الهيئة.

1. Cybersecurity Governance

1-1 Cybersecurity Policies and Procedures

and complied with by the organization as per related laws and regulations, and organizational requirements. Control level

1-1-1

zation must document, approve, and implement a customized set of cybersecurity policies and procedures for OT/ICS systems or assets. With reference to the ECC control 1-3-3, the cybersecurity OT/ ICS policies and procedures must be supported by cybersecurity

1-1-2

requirements such as vendor recommendations, implementation guidelines, and configuration management guidelines. With reference to the ECC control 1-3-4, OT/ICS cybersecurity policies and procedures must be reviewed periodically and/

1-1-3

or when there is a change in the risks landscape, organizational structure, and/or process changes.

1-2-1-1 Cybersecurity roles and responsibilities (RACI) assignment for all stakeholders of the OT/ICS assets must be defined, documented, communicated and approved by the Authorizing

1-2 Cybersecurity Roles and Responsibilities

implementing the operational technology cybersecurity controls (OTCC) within the organization. Control level

1-2-1

Official while ensuring there is no conflict of interest.

1-2-1-2 Cybersecurity roles and responsibilities related to OT/ ICS assets must be assigned to the cybersecurity function in the organization.

1-3-1-1 OT/ICS cybersecurity risk management methodology

1-3 Cybersecurity Risk Management

protect the organization’s OT/ICS assets as per organizational policies and procedures, and related laws and regulations. Control level

1-3-1

within the Process Hazard Analysis (PHA) which is applied with any change in operations and/or procedures in Plants.

1-3-1-2 Cybersecurity risk assessment for OT/ICS assets must be conducted periodically while ensuring to include risks associated with signing contracts and agreements with OT/ICS related third-party organizations and/or upon changes in related regulatory requirements as part of the assessment.

1-3-1-3 Risk register for OT/ICS cybersecurity risks must be included as part of the organization’s risk register.

1-3-1-4 Appropriate level assignment to facilities which include (OT/ICS) must be conducted based on approved methodology.

1-3-1-5 Include a qualitative analysis of cybersecurity risks

1-3-1-6 In the event that cybersecurity requirements cannot be implemented within the OT/ICS environment, the specific justifications for not applying those requirements must be documented and approved by the respective cybersecurity function and the Authorizing Official.

1-3-1-7 In the event of risk acceptance, alternative cybersecurity controls must be clearly defined, documented, approved by the Authorizing Official, and implemented effectively for a definedperiod of time while reassessing the risk continuously.

1-4-1-1 Cybersecurity requirements must be part of OT/ICS project’s lifecycle.

1-4-1-2 Cybersecurity requirements must be included as part of any functional and acceptance testing and evaluation process (such as Factory Acceptance Testing “FAT” , Site Acceptance Test-

1-4 Cybersecurity in Industrial Control System Project Management

and availability of OT/ICS assets as per organization policies and procedures, and related laws and regulations. Control level

1-4-1

ing “SAT”, Commissioning Testing, Change Testing, Integration Testing and Source Code Review).

1-4-1-3 Secure-by-design principles must be included as part of security architectural designs for OT/ICS environments.

1-4-1-4 System development environments including testing environment and integration platforms must be protected. Cybersecurity requirements within the organization’s OT/ICS

1-4-2

project management must be reviewed, and their implementation effectiveness is measured and evaluated periodically.

1-5 Cybersecurity in Change Management

in OT/ICS environment by exercising due diligence analysis and control of the changes. Control level

1-5-1

The cybersecurity requirements must be a key part of the overall requirements of OT/ICS change management. Cybersecurity requirements within the organization’s OT/ICS

1-5-2

change management lifecycle must be implemented. In addition to the ECC controls 1-6-2 and 1-6-3, cybersecurity requirements in OT/ICS change management must include, at a minimum, the following:

1-5-3-1 Cybersecurity requirements are part of the change management lifecycle.

1-5-3-2 Changes are validated in a separate environment prior to implementing the changes on the production environment.

1-5-3

1-5-3-3 In the event that OT/ICS devices are replaced with different, but functionally equivalent devices, whether in design, testing, or operation environments, the cybersecurity of the replacement device must be validated prior to being utilized in operational environment.

1-5-3-4 Restricted processes for exceptional changes must be implemented.

1-5-3-5 Automated configuration and asset change detection mechanisms must be implemented. Cybersecurity requirements within the organization’s OT/ICS

1-5-4

change management requirements must be reviewed, and their implementation effectiveness is measured and evaluated periodically.

1-6 Periodical Cybersecurity Review and Audit

with organizational policies and procedures, as well as related national and international laws, regulations and agreements. Control level

1-6-1

rity function must review the implementation of (OTCC-1:2022) controls at least annually. With reference to ECC control 1-8-2, the implementation of

1-6-2

(OTCC-1:2022) controls must be reviewed by independent parties within the organization, outside the cybersecurity function at least once every three years.

1-7 Cybersecurity in Human Resources

(employees and third party personnel) are managed efficiently prior to employment, during employment, after termination/separation as per organizational policies and procedures, and related laws and regulations. Control level

1-7-1

must include, at a minimum, screening or vetting of all personnel (including employees, contractors and subcontractors) who have access or can utilize OT/ICS assets prior to granting them access. With reference to the ECC control 1-9-6, the cybersecurity requirements for cybersecurity in human resources in OT/ICS must

1-7-2

be reviewed, and their implementation effectiveness is measured and evaluated periodically.

1-8 Cybersecurity in Human Resources

required cybersecurity awareness. It is also to ensure that personnel is provided with the required cybersecurity training, skills, and credentials needed to accomplish their cybersecurity responsibilities and to protect the organization’s OT/ICS assets. Control level

1-8-1

curity awareness program must include a secure and safe interaction with the OT/ICS assets or systems. In addition to subcontrols in the ECC control 1-10-4 1-10-4, cybersecurity requirements in OT/ICS cybersecurity awareness and training program must include, at a minimum, the following:

1-8-2-1 customized training, qualifications, knowledge, and professional skillsets must be provided to all personnel with access to the OT/ICS assets. The organization is encouraged to utilize the

1-8-2

reference material provided in the Saudi Cybersecurity Workforce Framework (SCyWF).

1-8-2-2 Participation in OT/ICS authorized and/or specialized organizations and groups must be encouraged to stay up-to-date on common cybersecurity practices.

2-1-1-1 OT/ICS assets inventory must be developed in electronic format for all OT/ICS assets, and reviewed periodically.

2-1-1-2 Automated solution to collect asset inventory information must be utilized.

2. Cybersecurity Defense

2-1 Asset Management

ments to maintain the production uptime, safe operations, confidentiality, integrity, and availability of OT/ICS assets. Control level

2-1-1

In addition to the controls in ECC subdomain 2-1, cybersecurity requirements for asset management in OT/ICS environment must include, at a minimum, the following:

2-1-1-3 OT/ICS asset inventory must be stored securely.

2-1-1-4 Asset owners for all OT/ICS assets must be identified and involved throughout the relevant asset inventory management lifecycle.

2-1-1-5 Criticality rating for all assets must be assigned, documented, and approved by asset owners. With reference to the ECC control 2-1-6, the cybersecurity re-

2-1-2

quirements for managing OT/ICS assets must be reviewed, and their implementation effectiveness is measured and evaluated periodically.

2-2-1-1 Identity and access management lifecycle for OT/ICS is separated and independent from Information Technology (IT) including centrally managed identity and access management solutions.

2-2-1-2 Service accounts must be managed securely for OT/ICS services, applications, systems, and devices that are separated and disconnected from interactive users account logins.

2-2-1-3 Default credentials for all OT/ICS assets must be changed, disabled, or removed.

2-2-1-4 Sessions must be managed securely, including session authenticity, session lockout, and session timeout termination.

2-2-1-5 Automatic disabling/removing of service accounts, pro-

2-2 Identity and Access Management

unauthorized access and allow only authorized access for users, which are necessary to accomplish assigned tasks. Control level

2-2-1

grams, or accounts related to (OT/ICS) assets must be prevented, except for monitoring systems.

2-2-1-6 Dual approval and explicit privilege escalation mechanisms for sensitive actions within the OT/ICS environment must be employed.

2-2-1-7 Remote access to the OT/ICS networks must be restricted and exceptionally enabled when necessary and justified. A cybersecurity risk assessment must be conducted prior to granting a remote access and its associated risks are monitored and managed. The granted access must be through trusted multi-factor authenticated and encrypted channel for a defined period of time and with limited access privilege. The remote access session must be monitored and recorded while its time duration and granted user's privilege must be in accordance with the cybersecurity risk assessment.

2-2-1-8 Secure and complex password standards must be implemented.

2-2-1-9 Secure mechanisms to store OT/ICS assets’ passwords must be used.

2-2-1-10 With reference to the ECC subcontrol 2-2-3-5, users’ identities and access rights must be reviewed in response to cybersecurity incidents, personnel roles changes, or whenever there is a

2-2-1-11 Access shall be immediately revoked when no longer needed. With reference to the ECC control 2-2-4, the cybersecurity requirements for identity and access management in OT/ICS env

2-2-2

ronment must be reviewed, and its implementation effectiveness is measured and evaluated periodically.

2-3-1-1 Advanced, up-to-date protection mechanisms and techniques must be utilized and securely managed to block and protect from malware, Advanced Persistent Threats (APT), malicious files, and activities.

2-3 System and Processing Facilities Protection

To ensure the protection of OT/ICS systems and processing facilities (including workstations, servers and Safety Instrumented Systems “SIS”) against cyber risks. Control level

2-3-1

2-3-1-2 Periodic security configurations’ review and hardening must be conducted in alignment with the vendor implementation guidance or recommendations with respect to cybersecurity and organization’s formal change management mechanisms.

2-3-1-3 Periodic security patches and upgrades must be implemented in alignment with vendor implementation guidance or recommendations with respect to cybersecurity and organization’s formal change management mechanisms.

2-3-1-4 Principles of least privilege and least functionality must be applied.

2-3-1-5 Safety Instrumented Systems (SIS) controllers must be configured in appropriate modes at all times, which prevent any unauthorized changes, and changes to improper modes are limited to exceptional cases with a specific period of time.

2-3-1-6 Application whitelisting techniques or other similar techniques must be deployed to limit the applications that are allowed to run in OT/ICS environment.

2-3-1-7 OT/ICS assets must be managed through dedicated, segmented and hardened Engineering Workstation (EWS) and Human-Machine Interface (HMI) for management purposes and maintenance.

2-3-1-8 External storage media is scanned and analyzed against malware and APT. The scan must be executed in an isolated and secure environment.

2-3-1-9 Usage of external storage media in the production en-

2-3-1-10 Systems’ logs and critical files must be protected from unauthorized access, tampering, illegitimate modification and/or deletion.

2-3-1-11 Unauthorized applications, scripts, tasks, and changes must be detected and analyzed.

2-3-1-12 New communications sessions and commands execution must be detected and analyzed.

2-3-1-13 Direct communications between the OT/ICS environment and external hosts must be detected and analyzed. With reference to the ECC control 2-3-4, the cybersecurity requirements for system and processing facilities protection in OT/

2-3-2

ICS environment must be reviewed, and their implementation effectiveness is measured and evaluated periodically.

2-4-1-1 OT/ICS environment must be segmented logically or physically from other environments or networks.

2-4-1-2 Different zones within the OT/ICS environment must be segmented logically or physically in accordance with the zone’s appropriate level that isolates data flows and directs traffic to "Choke Points”.

2-4-1-3 Safety Instrumented Systems (SIS) must be segmented logically or physically from other OT/ICS networks.

2-4-1-4 Wireless technologies (such as Wi-Fi, Bluetooth, cellular, satellite, etc.) must be restricted, and to only be used when the technology meets specific business requirements and is properly

2-4 Networks Security Management

To ensure the protection of the organization’s OT/ICS networks from cyber risks. Control level

2-4-1

In addition to subcontrols in ECC control 2-5-3, cybersecurity requirements for network security management in OT/ICS environment must cover, at a minimum, the following:

2-4-1-5 Wireless technologies must be segmented logically or physically from other OT/ICS networks.

2-4-1-6 Network communications, services, and connection points between different zones must be limited to the minimum to meet operational, maintenance, and safety requirements.

2-4-1-7 Direct exposure of common remote authentication and access management services on external-facing hosts must be prevented.

2-4-1-8 Only authorized business-critical services are accessible from the internal OT/ICS networks, and accessibility to services with known vulnerabilities must be limited to the greatest extent possible.

2-4-1-9 Direct communications between corporate zone and OT/ ICS zones must be prevented, and direct all the required connections through dedicated, secured, and hardened jump host/solution in the DMZ zone.

2-4-1-10 Remote access point in the DMZ zone must not be connected to the OT/ICS networks unless needed, while ensuring that the session is multi-factor authenticated, recorded, and established for a defined period of time only.

2-4-1-11 Proxies must be employed between the corporate and OT/ICS zones for all machine-to-machine traffic.

2-4-1-12 Dedicated gateways must be used to segment OT/ICS networks from corporate zone.

2-4-1-13 Dedicated DMZ zone must be used to reside any system that needs services provided by corporate zone.

2-4-1-14 Strict limitation on enabling/usage of industrial protocols and ports to the minimum to meet operational, maintenance, and safety requirements.

2-4-1-15 Periodic patches and upgrades for production assets must be certified by respective vendor and tested in a separate environment prior to implementation.

2-4-1-16 Details related to network architecture and topology, zones, network data flows, connectivity, and interdependencies must be documented, updated, and maintained. With reference to the ECC control 2-5-4, the cybersecurity requirements for network security management in OT/ICS environ-

2-4-2

ment must be reviewed, and their implementation effectiveness is measured and evaluated periodically.

2-5-1-1 Usage of mobile devices for OT/ICS must be restricted unless specifically required. A cybersecurity risk assessment must be conducted where risks must be defined and managed. A management approval must be granted by respective cybersecurity function for a defined period of time only in alignment with organization’s formal access management mechanisms.

2-5-1-2 Mobile devices must only be used for their intended purposes and in compliance with cybersecurity requirements of its

2-5 Mobile Devices Security

devices, network test devices, etc.) from cyber risks and to ensure the secure handling of sensitive data and the organization’s information. Control level

2-5-1

respective zones prior to being connected to OT/ICS environment, and are hardened and updated with the latest security patches and scanned against malware and APT.

2-5-1-3 Limited and approved list of mobile devices must be defined while ensuring that only these mobile devices can be connected to OT/ICS environment.

2-5-1-4 Centralized management of mobile devices must be deployed.

2-5-1-5 Encryptions mechanisms must be used for mobile devices authorized to access the OT/ICS assets. With reference to the ECC control 2-6-4, the cybersecurity re-

2-5-2

quirements for mobile devices security in OT/ICS environment must be reviewed, and their implementation effectiveness is measured and evaluated periodically.

2-6-1-1 Electronic and physical data (at rest and in transit) must be protected at a level consistent with its classification.

2-6-1-2 Data Leakage Prevention (DLP) mechanisms must be used to protect the classified data and information.

2-6 Data and Information Protection

and information as per organizational policies and procedures, and related laws and regulations. Control level

2-6-1

In addition to subcontrols in the ECC control 2-7-3, cybersecurity requirements for data and information protection in OT/ICS must include, at a minimum, the following:

2-6-1-3 Secure wiping mechanisms for configuration details and stored data from OT/ICS assets prior to decommissioning must be implemented.

2-6-1-4 Transfer or usage of OT systems’ data in any environment other than production environment must be limited, except after applying strict controls for protecting that data. With reference to the ECC control 2-7-4, the cybersecurity requirements for data and information protection in OT/ICS envi-

2-6-2

ronment must be reviewed, and their implementation effectiveness is measured and evaluated periodically.

2-7 Cryptography

To ensure the proper and efficient use of cryptography to protect information assets as per organizational policies and procedures, and related laws and regulations. Control level

2-7-1

tion must ensure that cryptographic technologies used in OT/ICS environment are aligned with the NCA National Cryptographic Standard (NCS1:2020). With reference to the ECC control 2-8-4, the cybersecurity re-

2-7-2

quirements for cryptography in OT/ICS environment must be reviewed, and their implementation effectiveness is measured and evaluated periodically.

2-8-1-1 Backups for all OT/ICS assets must be covered and stored in centralized and offline locations.

2-8-1-2 OT/ICS assets’ critical configuration files and engineering files must be included in the backup’s scope.

2-8 Backup and Recovery Management

information systems and software configurations from cyber risks as per organizational policies and procedures, and related laws and regulations. Control level

2-8-1

In addition to subcontrols in the ECC control 2-9-3, cybersecurity requirements for backup and recovery management in OT/ICS must include, at a minimum, the following:

2-8-1-3 Backups must be performed periodically as per the defined OT/ICS assets classification and their associated risks.

2-8-1-4 Access, storage, and transfer of backups and their mediums must be secured to ensure their protection against damage, change, or unauthorized access. With reference to the ECC control 2-9-4, the cybersecurity requirements for backup and recovery management in OT/ICS envi-

2-8-2

ronment must be reviewed, and their implementation effectiveness is measured and evaluated periodically.

2-9-1-1 Scope and activities of vulnerability assessments must be defined for OT/ICS environment as part of organization’s formal vulnerability management while ensuring limited or no impact on the production environment.

2-9 Vulnerabilities Management

prevent or minimize the probability of exploiting these vulnerabilities to launch cyber-attacks against the organization. Control level

2-9-1

In addition to subcontrols in the ECC control 2-10-3, cybersecurity requirements for vulnerability management in OT/ICS must cover, at a minimum, the following:

2-9-1-2 With reference to the ECC subcontrol 2-10-3-3, remediation of newly discovered critical vulnerabilities presenting significant risks to the OT/ICS environment must be performed in a timely manner.

2-9-1-3 With reference to the ECC subcontrol 2-10-3-1, vulnera3 6 12 bility assessment for OT/ICS systems must be conducted periodiMonths Months Months cally. With reference to the ECC control 2-10-4, the cybersecurity re-

2-9-2

quirements for vulnerability management in OT/ICS environment must be reviewed, and their implementation effectiveness is measured and evaluated periodically.

2-10-1-1 With reference to the ECC subcontrol 2-11-3-1, scope and activities of penetration testing must be defined to ensure the coverage of OT/ICS environment and networks connected to the operational network by qualified team.

2-10-1-2 With reference to the ECC subcontrol 2-11-3-2, penetration testing must only be conducted with limited or no impact on

2-10 Penetration Testing

bilities through simulated cyber-attacks to discover unknown weaknesses within the technical infrastructure that may lead to a cyber-breach. Control level

2-10-1

the production environment, or on an identical separate environment.

2-10-1-3 With reference to the ECC subcontrol 2-11-3-2, penetra3 6 12 tion testing for OT/ICS systems must be conducted periodically. Months Months Months

2-10-1-4 Alternative testing methods (such as passive testing mechanisms) must be defined and Implemented to collect relevant information when a potential impact to operational production environment may occur. With reference to the ECC control 2-11-4, the cybersecurity re-

2-10-2

quirements for penetration testing in OT/ICS environment must be reviewed, and their implementation effectiveness is measured and evaluated periodically.

2-11-1-1 Cybersecurity event logs and audit trails must be activated for all OT/ICS assets.

2-11-1-2 Failure attempts in accessing the organization’s monitoring systems must be detected and logged.

2-11-1-3 Continuous, in-depth cybersecurity log review and monitoring, covering all logs and audit trails must be conducted.

2-11-1-4 Monitoring, detecting, and analyzing User Behaviors Analytics (UBA) must be performed.

2-11 Cybersecurity Event Logs and Monitoring Management

detection of potential cyber-attacks in order to prevent or minimize the negative impacts on the organization’s operations. Control level

2-11-1

In addition to subcontrols in the ECC control 2-12-3, cybersecurity requirements for cybersecurity event logs and monitoring management in OT/ICS must include, at a minimum, the following:

2-11-1-5 Upload or download activities of OT/ICS assets including Safety Instrumented Systems (SIS) must be detected.

2-11-1-6 All remote access sessions must be monitored.

2-11-1-7 Malicious events must be detected and analyzed.

2-11-1-8 Logging and monitoring of new alerts when new or unauthorized devices are connected to the OT/ICS networks must be performed.

2-11-1-9 OT/ICS Threat Intelligence must be used and incorporated to regularly tune and refresh alerts of Security Information and Event Management (SIEM) technologies.

2-11-1-10 All access control points between the network security boundaries and external connections must be monitored. With reference to the ECC control 2-12-4, the cybersecurity requirements for cybersecurity event logs and monitoring manage-

2-11-2

ment in OT/ICS environment must be reviewed, and their implementation effectiveness is measured and evaluated periodically.

2-12-1-1 OT/ICS cybersecurity incident response plans must be integrated and aligned with organizational plans and its procedures such as IT incident response plans, crisis management, and Business Continuity Plan (BCP).

2-12-1-2 Formal incident response and root cause analysis for any detected cybersecurity incidents must be conducted.

2-12-1-3 Sequence of incident response activities necessary to restore normal operations must be defined.

2-12-1-4 Incident communications plan must be established.

2-12 Cybersecurity Incident and Threat Management

bersecurity incidents and threats to prevent or minimize negative impacts on organization’s OT/ICS operation. Control level

2-12-1

In addition to subcontrols in the ECC Control 2-13-3, cybersecurity requirements for cybersecurity incident and threat management in OT/ICS must include, at a minimum, the following:

2-12-1-5 OT/ICS including Safety Instrumented Systems (SIS) recovery procedures must be included in the incident response, system recovery plans, and business continuity plans.

2-12-1-6 Trainings and skillsets for the organization’s personnel (including employees, contractors and subcontractors) to respond to OT/ICS cybersecurity incidents must be provided.

2-12-1-7 Cybersecurity incident response capabilities, readiness, and plan must be periodically tested by performing cyber-attack simulations exercises.

2-12-1-8 Threat Intelligence information must be used to identify Tactics, Techniques, and Procedures (TTPs) of activity groups targeting OT/ICS systems. With reference to the ECC control 2-13-4, the cybersecurity requirements for cybersecurity incident and threat management in

2-12-2

OT/ICS environment must be reviewed, and their implementation effectiveness is measured and evaluated periodically.

2-13-1-1 List of personnel with authorized access to facilities and sensitive locations where OT/ICS assets reside must be maintained.

2-13-1-2 Real-time physical intrusion detection alarms and surveillance equipment, and proper mechanisms must be implemented to recognize potential intrusions and apply the approved response actions.

2-13-1-3 Physical access points and perimeter to sensitive OT/ICS areas shall be protected and ensure continuous monitoring.

2-13-1-4 Safeguards, such as locks on cabinets containing control

2-13 Physical Security

To ensure the protection of OT/ICS assets from unauthorized physical access, loss, theft, and damage. In addition to subcontrols in the ECC Control 2-14-3, cybersecurity requirements for physical security in OT/ICS environment must include, at a minimum, the following:

2-13-1

systems or sensitive assets related to OT/ICS, must be utilized to prevent unauthorized access to devices that could provide a mechanism to compromise the OT/ICS assets.

2-13-1-5 Strict limitation must be enforced on the physical access to all OT/ICS assets, including Safety Instrumented Systems (SIS).

2-13-1-6 Visitor access records to restricted locations where OT/ ICS reside must be maintained.

2-13-1-7 Work being performed by contractor or vendor personnel must be monitored.

2-13-1-8 Trainings and skillsets for the organizational security guards must be provided in line with roles and responsibilities with respect to OT/ICS physical security.

2-13-1-9 Physical security capabilities and readiness must be periodically tested by performing simulation exercises (such as social engineering). With reference to the ECC control 2-14-4, the cybersecurity re-

2-13-2

quirements for physical security in OT/ICS environment must be reviewed, and their implementation effectiveness is measured and evaluated periodically.

3-1-1-1 Activities necessary to sustain minimum operations of the OT/ICS systems must be defined.

3-1-1-2 Redundant OT/ICS networks, connections, and devices must be implemented in accordance to the periodic cybersecurity risk assessment.

3-1-1-3 OT/ICS cybersecurity requirements must be incorporated into the Business Continuity Plan (BCP), Business Impact

3. Cybersecurity Resilience

3-1 Cybersecurity Resilience Aspects of Business Continuity Management (BCM)

zation’s business continuity management and to remediate and minimize the impacts on OT/ICS environment from disasters caused by cybersecurity incidents. Control level

3-1-1

Analysis (BIA), Recovery Time Objectives (RTO), and Recovery Point Objectives (RPO).

3-1-1-4 OT/ICS cybersecurity requirements must be incorporated into the Disaster Recovery Plan (DRP) including cybersecurity-related disaster scenarios, system failure handling procedures, and operational continuity management procedures.

3-1-1-5 In the event of a system failure due to a cybersecurity incident, OT/ICS assets or systems must operate on an acceptable safe mode to achieve a continuous operation.

3-1-1-6 Periodic testing and simulation exercises (e.g. tabletop exercises "TTX”) must be conducted to test the effectiveness of OT/ICS related DRP and BCP and complete incident root cause analysis. With reference to the ECC control 3-1-4, the cybersecurity requirements for cybersecurity resilience aspects of business con-

3-1-2

tinuity management in OT/ICS environment must be reviewed, and their implementation effectiveness is measured and evaluated periodically.

4-1-1-1 Cybersecurity requirements are included during procurement lifecycle for OT/ICS products and services.

4-1-1-2 Cybersecurity requirements for third-party evaluation, se-

4. Third-Party Cybersecurity

4-1 Third-Party Cybersecurity

to third-parties, including manufactures of OT/ICS-related hardware and software, vendors of OT/ICS products and suppliers of OT/ICS-related services as per organizational policies and procedures, and related laws and regulations. Control level

4-1-1

lection, and information sharing must be defined.

4-1-1-3 Third-party contractors and vendors must use formal and documented Secure Development Life Cycle (SDLC) practices for systems and components designed or deployed in OT/ICS environment.

4-1-1-4 Periodic cybersecurity assessment and audits of third-party providers must be conducted to ensure the mitigation of any identified cyber threats. With reference to the ECC control 4-1-4, the cybersecurity requirements for third-party cybersecurity in OT/ICS environment

4-1-2

must be reviewed, and their implementation effectiveness is measured and evaluated periodically.

أُعدت هذه الصفحة من النص الرسمي حرفيًا عبر إحكام من سايبرز.بز · افتح المكتبة التفاعلية