Skip to main content
Guidance

Operational Technology

Making sense of cyber security in OT environments.

Pages

Page 8 of 37

Principle 5: Understand and document third-party risks to your OT system

Many OT systems are managed or maintained by third parties, such as manufacturers, integrators, or managed service providers (MSPs). When these groups have access to your environment, they add risks that require additional consideration, as you don’t have direct control over the security of the delivered system. 

The NCSC has produced supply chain security guidance on how to effectively manage these risks. IEC 62443-4-1 (secure product development lifecycle requirements) and IEC 62443-2-4 (security program requirements for IACS service providers) provides some additional advice specific to industrial automation and control systems.

At a minimum, you should be able to answer the following 3 questions for third parties connecting to the network:


Summary

Your organisation should have a detailed understanding of each external connection and its corresponding trust level, ensuring that these levels dictate the necessary security controls for protecting OT data and systems. You must verify compliance with the "Browse-Down" model, where high trust systems manage lower trust systems, and have processes in place to validate the security controls of third-party administration systems against your organisational standards.


Summary

Your organisation should have a documented and detailed understanding of how contractual or regulatory requirements from third parties impact your ability to apply security controls. This documentation should include any compensating controls in place that enable you to manage this risk.


Summary

Your organisation should have an established process  to assess any new assets being installed by third-parties and to document any risks these assets may present to the wider system. Out of band management should be removed where feasible to remove these risks. Where this is not possible, you should have a clear documented understanding of the technical controls put in place by the third party to harden the access. 

Published

Reviewed

Version

1.0