Edge Register

Depot and cash centre

Scanners, label printers, a routing PC, note counters or sorters, a vault system and a CCTV recorder, with a small office at the side.

How the register reads it

Also calledcash centre, parcel hub, archive store
FamilyDepot, warehouse and yard
Exposure by defaultUnattended: a skeleton crew in shifts and nobody at all between them; the yard gate is the perimeter. A line that says attended, unattended, public or hostile (outdoors, in transit, at sea) overrides it.
Link by defaultAlways: a fixed line, with the scanners falling back to their local buffer. A line that names the link (fibre, 4G, satellite, radio, offline) overrides it.
Regulated data by defaultNone; a line that names customer, staff, patient, card or controlled data adds it.
Runs plantNot by default; a line that names PLCs, SCADA, RTUs or HMIs adds it.
What a loss costsA depot offline scans to a buffer and catches up; a depot broken into loses the goods, the counters and whatever records were on the routing PC.
Contract focusDevice buffer and sync behaviour, repair and swap times, out-of-hours alarm response, secure disposal of scanners and recorders.

What each regime attaches

15 clauses across 6 regimes, on the class defaults

Shown on a register for the regimes you tick, by the exposure, link, data and plant the line states; with none ticked, the ISO 27001 rows are the default. Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27001:2022, with the 27002:2022 guidance beside it

Attaches to every site: the off-premises, equipment, media, endpoint, backup, redundancy, network and continuity controls of Annex A, by the site's exposure, link, data and plant. With nothing ticked these rows render as the default.

ISO 27001 7.4 Physical security monitoring

Continuously monitor premises for unauthorized physical access.

ISO 27002 7.4 guidance: Requires premises to be monitored continuously for unauthorised physical access. Supporting material frames this as continuous monitoring of physical security controls so that unauthorised entry and other physical security incidents are detected and responded to.

Evidence an auditor accepts: cctv_logs; access_control_logs; incident_reports
Common gap: logs not retained for required period
Source framework: ISO/IEC 27001:2022
ISO 27001 7.8 Equipment siting and protection

Site equipment securely and protect it.

ISO 27002 7.8 guidance: Requires equipment to be sited securely and protected. Older source material in the folder expands this as siting equipment to reduce unnecessary access into work areas, positioning and restricting the viewing angle of facilities handling sensitive data, isolating items needing special protection, and guarding against physical hazards such as theft, fire, water, dust, vibration, electrical interference and vandalism.

Evidence an auditor accepts: site_layout_plans; environmental_controls; physical_security_measures
Common gap: Assuming perimeter security covers equipment
Source framework: ISO/IEC 27001:2022
ISO 27001 7.9 Security of assets off-premises

Protect assets used or held off-site.

ISO 27002 7.9 guidance: Requires assets located away from the organisation's premises to be protected.

Evidence an auditor accepts: offsite_asset_inventory; transport_security_procedures; third_party_agreements
Common gap: Missing offsite asset register
Source framework: ISO/IEC 27001:2022
ISO 27001 7.13 Equipment maintenance

Maintain equipment correctly to preserve availability, integrity and confidentiality.

ISO 27002 7.13 guidance: Requires equipment to be maintained correctly, so that information stays available, intact and confidential.

Evidence an auditor accepts: maintenance_schedule; maintenance_logs; calibration_records
Common gap: no documented maintenance schedule
Source framework: ISO/IEC 27001:2022
ISO 27001 8.9 Configuration management

Establish, document, implement, monitor and review secure configurations for hardware, software, services and networks.

ISO 27002 8.9 guidance: Requires configurations of hardware, software, services and networks, including their security configurations, to be established, documented, implemented, monitored and reviewed. Supporting material frames this as a standing process that keeps systems configured securely and consistently.

Evidence an auditor accepts: baseline_configurations; change_control_records; configuration_audit_reports
Common gap: outdated baselines
Source framework: ISO/IEC 27001:2022

NIST SP 800-53 Rev 5

Attaches to every site: the PE family for the premises and the alternate work site, MP for the media, AC-17, AC-19 and AC-20 for remote access, mobile devices and external systems, the CP family for the sites that lose their link, SC-7 for the boundary and SI-7 and CM-8 for what runs there.

SP 800-53 CM-8 System component inventory

Requires an accurate inventory of system components that covers every component, avoids duplicate or cross system accounting, is held at the granularity needed for tracking and reporting, carries the information the organization has defined for accountability, and is reviewed and updated on a defined frequency.

Evidence an auditor accepts: Component inventory with the defined accountability fields populated; Reconciliation of the inventory against a discovery scan or cloud asset listing; Defined review frequency and evidence of review at that cadence
Common gap: Cloud and container assets absent because inventory is built from a fixed asset register
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-3 Physical access control

Requires physical access authorizations to be enforced at defined entry and exit points by verifying authorization before entry and controlling ingress and egress with defined mechanisms or guards, physical access audit logs to be kept, publicly accessible areas to be controlled, visitors to be escorted and their activity controlled in defined circumstances,...

Evidence an auditor accepts: Entry and exit point register showing the enforcement mechanism at each; Physical access audit logs from badge or guard systems; Visitor escort procedure and completed visitor logs
Common gap: Tailgating unaddressed, so an authorization check happens for only the first person through
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-6 Monitoring physical access

Requires physical access to the facility to be monitored so that physical security incidents are detected and responded to, physical access logs to be reviewed at a defined frequency and on defined events, and review and investigation results to be coordinated with the incident response capability.

Evidence an auditor accepts: Monitoring arrangements such as alarms, surveillance or guard patrols; Physical access log review records at the defined frequency; Records of event driven reviews following an incident or alarm
Common gap: Surveillance recorded but never reviewed unless something is already known to be wrong
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-18 Location of System Components. Position system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthorized access

Location of System Components. Position system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthorized access

Evidence an auditor accepts: The defined physical and environmental hazards that positioning is intended to mitigate; Floor plans or location documentation showing where system components sit relative to those hazards; Rationale linking each placement decision to the hazard it mitigates and to unauthorised access opportunity
Common gap: Placement driven by available space and cabling, with the hazard rationale written afterwards
Source framework: NIST SP 800-53 Rev 5
SP 800-53 SI-7 Software, firmware, and information integrity

Requires integrity verification tools to be employed to detect unauthorized changes to organization-defined software, firmware and information, and requires organization-defined actions to be taken when such unauthorized changes are detected.

Evidence an auditor accepts: Defined list of software, firmware and information subject to integrity verification; Integrity monitoring tool configuration and coverage report; Alerts generated by integrity checks and the response records
Common gap: Integrity monitoring produces constant noise from routine change and is therefore ignored
Source framework: NIST SP 800-53 Rev 5

CIS Controls v8

Attaches to every site: the asset inventory on all of them, anti-malware on the unattended and public ones and on plant, automated and isolated backups where the link is intermittent or absent, remote wipe and the VPN on portable and remote devices.

CIS v8 CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory

Establish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data, to include: end-user devices (including portable and mobile), network devices, non-computing/IoT devices, and servers. Ensure the inventory records the network address (if static), hardware address, machine name, enterp...

Evidence an auditor accepts: Evidence the safeguard is implemented: Establish and Maintain Detailed Enterprise Asset Inventory; Policy/standard covering CIS Control 1 (Inventory and Control of Enterprise Assets); Configuration / tooling output demonstrating the safeguard
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-10.1 Deploy and Maintain Anti-Malware Software

Deploy and maintain anti-malware software on all enterprise assets.

Evidence an auditor accepts: Evidence the safeguard is implemented: Deploy and Maintain Anti-Malware Software; Policy/standard covering CIS Control 10 (Malware Defenses); Configuration / tooling output demonstrating the safeguard
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8

ISO 22301:2019

Attaches the business continuity plans and procedures to every site, and the plan content and recovery clauses to the sites whose link is intermittent or absent.

ISO 22301 8.4.1 General

Implement and maintain a response structure enabling timely warning and communication to relevant interested parties, with plans and procedures to manage the organization through a disruption and to activate continuity solutions, identified and documented from the output of the selected strategies and solutions, and with procedures that are specific about im...

Evidence an auditor accepts: Documented response structure; Procedures stating immediate steps and the roles that take them; Traceability from selected strategies and solutions to the documented plans
Common gap: Procedures written for one rehearsed scenario, brittle against anything else
Source framework: ISO 22301:2019

DORA, the Digital Operational Resilience Act

Attaches Article 11 (response and recovery) to every site of a financial entity and Article 12 (backup, restoration and recovery) to the sites whose link is intermittent or absent; a site with no recovery objective is a finding.

DORA Art. 11 Response and recovery

Financial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.

Evidence an auditor accepts: ICT business continuity policy + response/recovery plans; Records of plan testing
Common gap: No ICT continuity/response/recovery plans
Source framework: DORA (Regulation (EU) 2022/2554)

NIST SP 800-207, zero trust architecture

Attaches the satellite-facility deployment scenario to every site and the two design tenets (every communication secured, every asset's posture monitored) to the sites where remote access is named. No regime page: it renders on the remote-access rows and the finding.

SP 800-207 SC-SATELLITE Deployment Scenario: Enterprise with Satellite Facilities

Applies ZTA to an organization with a headquarters plus geographically dispersed locations and remote workers that have no full enterprise-owned network.

Evidence an auditor accepts: ZTA design for remote workers and satellite sites; Policy coverage for off-network access
Common gap: VPN-only model treated as zero trust
Source framework: NIST SP 800-207

Questions for the hardware vendor

six, and one for the class

For the scanners, the routing PC, the counters or sorters and the recorder, over the fixed link:

  1. Can you show measured boot or firmware attestation on the equipment, and how a failed check reports back over the fixed link?
  2. How does the equipment take an update unattended over the fixed link, and how does it roll back on its own when the update fails part way?
  3. Can a lost or stolen unit be wiped remotely, and what happens to the wipe command while the unit is offline?
  4. Is local storage on the equipment encrypted at rest with the key held off the device, and can that be verified from the fleet console?
  5. Can the equipment be recovered to a known state by a non-technical person on site, without a technician's visit?
  6. What spares, lead times and end-of-support dates apply to the equipment, and who holds the spares nearest the site?

For this class: How long do the scanners buffer offline, and what happens to the buffered records if a scanner is lost before it syncs?

Findings this class can raise

Do this for every site on your list

Paste the list and get this reading for every site at once, with the link, the exposure, the data held, the findings and the duty rows per regime. Eight sites free, no account.

Build my edge register

Store and shop floor · Warehouse and distribution centre