Edge Register

Offshore platform and rig

Process control and safety systems, drilling systems, crew administration PCs and the medic's records, on a satellite link shared by everyone aboard.

How the register reads it

Also calledrig, FPSO, drilling platform
FamilyField and temporary site
Exposure by defaultHostile: weather, salt, explosive atmospheres in places, and a crew that rotates. A line that says attended, unattended, public or hostile (outdoors, in transit, at sea) overrides it.
Link by defaultIntermittent: satellite with a strict link budget, microwave to a neighbouring platform where there is one. A line that names the link (fibre, 4G, satellite, radio, offline) overrides it.
Regulated data by defaultPersonal; a line that names the data overrides it.
Runs plantYes: the OT overlay (NIST SP 800-82 Rev 3) attaches, and IEC 62443 is named beside it as a reference.
What a loss costsA platform cut off runs on its own systems as designed; a control system reached over the shared satellite link is process safety on someone else's command.
Contract focusSatellite service and link budget, control-system vendor access terms, safety-system isolation evidence, spares aboard.

What each regime attaches

43 clauses across 8 regimes, on the class defaults

Shown on a register for the regimes you tick, by the exposure, link, data and plant the line states; with none ticked, the ISO 27001 rows are the default. Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27001:2022, with the 27002:2022 guidance beside it

Attaches to every site: the off-premises, equipment, media, endpoint, backup, redundancy, network and continuity controls of Annex A, by the site's exposure, link, data and plant. With nothing ticked these rows render as the default.

ISO 27001 5.14 Information transfer

Put rules, procedures or agreements in place for every way information moves, inside and outside the organization.

ISO 27002 5.14 guidance: Requires transfer rules, procedures or agreements to be in place for every type of transfer facility, covering transfers within the organisation and between the organisation and outside parties.

Evidence an auditor accepts: transfer_policy; transfer_agreements; transfer_procedures
Common gap: Reliance on informal verbal agreements
Source framework: ISO/IEC 27001:2022
ISO 27001 5.30 ICT readiness for business continuity

Plan, implement, maintain and test ICT readiness against business continuity objectives.

ISO 27002 5.30 guidance: Requires ICT readiness to be planned, implemented, maintained and tested against business continuity objectives and ICT continuity requirements. Supporting material frames this as ICT infrastructure and resources being resilient enough to carry business operations through disruption.

Evidence an auditor accepts: ict_continuity_plan; readiness_test_results; resource_allocation_records
Common gap: Testing frequency not aligned with risk
Source framework: ISO/IEC 27001:2022
ISO 27001 6.7 Remote working

Apply security measures when people access, process or store information outside the organization's premises.

ISO 27002 6.7 guidance: Requires security measures to be implemented when personnel work remotely, protecting information that is accessed, processed or stored outside the organisation's premises.

Evidence an auditor accepts: remote_access_policy; secure_connection_mechanisms; endpoint_security
Common gap: Missing MFA for remote access
Source framework: ISO/IEC 27001:2022
ISO 27001 7.8 Equipment siting and protection

Site equipment securely and protect it.

ISO 27002 7.8 guidance: Requires equipment to be sited securely and protected. Older source material in the folder expands this as siting equipment to reduce unnecessary access into work areas, positioning and restricting the viewing angle of facilities handling sensitive data, isolating items needing special protection, and guarding against physical hazards such as theft, fire, water, dust, vibration, electrical interference and vandalism.

Evidence an auditor accepts: site_layout_plans; environmental_controls; physical_security_measures
Common gap: Assuming perimeter security covers equipment
Source framework: ISO/IEC 27001:2022
ISO 27001 7.9 Security of assets off-premises

Protect assets used or held off-site.

ISO 27002 7.9 guidance: Requires assets located away from the organisation's premises to be protected.

Evidence an auditor accepts: offsite_asset_inventory; transport_security_procedures; third_party_agreements
Common gap: Missing offsite asset register
Source framework: ISO/IEC 27001:2022
ISO 27001 7.10 Storage media

Manage storage media across acquisition, use, transport and disposal per classification and handling rules.

ISO 27002 7.10 guidance: Requires storage media to be managed across their whole life cycle, covering acquisition, use, transportation and disposal, in accordance with the organisation's classification scheme and handling requirements. Older source material adds that disposal should follow formal procedures scaled to the sensitivity of the information held, and that media in transit needs protection against unauthorised access, misuse and corruption.

Evidence an auditor accepts: media_inventory; media_handling_procedures; media_transport_logs
Common gap: No documented classification for media
Source framework: ISO/IEC 27001:2022
ISO 27001 7.13 Equipment maintenance

Maintain equipment correctly to preserve availability, integrity and confidentiality.

ISO 27002 7.13 guidance: Requires equipment to be maintained correctly, so that information stays available, intact and confidential.

Evidence an auditor accepts: maintenance_schedule; maintenance_logs; calibration_records
Common gap: no documented maintenance schedule
Source framework: ISO/IEC 27001:2022
ISO 27001 8.1 User end point devices

Protect information stored on, processed by or reachable through user endpoints.

ISO 27002 8.1 guidance: Requires information stored on, processed by or accessible through user endpoint devices to be protected.

Evidence an auditor accepts: device_inventory; endpoint_security_settings; encryption_and_data_protection
Common gap: Incomplete device inventory
Source framework: ISO/IEC 27001:2022
ISO 27001 8.7 Protection against malware

Implement malware protection backed by user awareness.

ISO 27002 8.7 guidance: Requires malware protection to be put in place and reinforced by suitable awareness among users.

Evidence an auditor accepts: anti_malware_policy; endpoint_protection; user_awareness_program
Common gap: Outdated malware signatures not regularly updated
Source framework: ISO/IEC 27001:2022
ISO 27001 8.9 Configuration management

Establish, document, implement, monitor and review secure configurations for hardware, software, services and networks.

ISO 27002 8.9 guidance: Requires configurations of hardware, software, services and networks, including their security configurations, to be established, documented, implemented, monitored and reviewed. Supporting material frames this as a standing process that keeps systems configured securely and consistently.

Evidence an auditor accepts: baseline_configurations; change_control_records; configuration_audit_reports
Common gap: outdated baselines
Source framework: ISO/IEC 27001:2022
ISO 27001 8.13 Information backup

Maintain and regularly test backups of information, software and systems per the backup policy.

ISO 27002 8.13 guidance: Requires backup copies of information, software and systems to be maintained and regularly tested, in line with the agreed topic specific policy on backup. Supporting SME guidance treats regular creation of backups together with tested recovery as the substance of the control, not the copy on its own.

Evidence an auditor accepts: backup_policy; backup_schedule; backup_test_reports
Common gap: infrequent restore testing
Source framework: ISO/IEC 27001:2022
ISO 27001 8.14 Redundancy of information processing facilities

Build enough redundancy into processing facilities to meet availability requirements.

ISO 27002 8.14 guidance: Requires information processing facilities to be implemented with redundancy sufficient to meet the availability requirements placed on them.

Evidence an auditor accepts: redundancy_design; capacity_planning; failover_testing
Common gap: reliance on undocumented manual backups
Source framework: ISO/IEC 27001:2022
ISO 27001 8.20 Networks security

Secure, manage and control networks and network devices.

ISO 27002 8.20 guidance: Requires networks and network devices to be secured, managed and controlled in order to protect the information carried in systems and applications.

Evidence an auditor accepts: network_topology_diagrams; firewall_rule_sets; network_access_control_lists
Common gap: outdated topology diagrams
Source framework: ISO/IEC 27001:2022
ISO 27001 8.22 Segregation of networks

Segregate groups of services, users and systems in the network.

ISO 27002 8.22 guidance: Requires segregation within the organisation's networks, keeping groups of information services, of users and of systems apart from one another.

Evidence an auditor accepts: network_segmentation_policy; network_topology_diagrams; firewall_rule_set_documents
Common gap: Informal or outdated network maps used instead of documented diagrams
Source framework: ISO/IEC 27001:2022
ISO 27001 8.24 Use of cryptography

Define and implement rules for effective use of cryptography and key management.

ISO 27002 8.24 guidance: Requires defined and implemented rules on using cryptography effectively, including how cryptographic keys are managed.

Evidence an auditor accepts: encryption_policy; key_management_procedures; algorithm_inventory
Common gap: Missing documented key lifecycle
Source framework: ISO/IEC 27001:2022

NIST SP 800-53 Rev 5

Attaches to every site: the PE family for the premises and the alternate work site, MP for the media, AC-17, AC-19 and AC-20 for remote access, mobile devices and external systems, the CP family for the sites that lose their link, SC-7 for the boundary and SI-7 and CM-8 for what runs there.

SP 800-53 AC-19 Access control for mobile devices

Requires documented configuration settings, connection rules and implementation guidance for mobile devices the organization controls, including their use away from controlled areas, and explicit authorization before any such device connects to an organizational system.

Evidence an auditor accepts: Mobile device standard covering encryption, lock, patching and off-site use; Mobile device management enrolment report reconciled to the device inventory; Authorization records for mobile device connection to each in scope system
Common gap: Personally owned devices reach corporate mail with no enrolment or authorization
Source framework: NIST SP 800-53 Rev 5
SP 800-53 AC-20 Use of external systems

Requires terms to be established, or existing external system relationships identified, before authorized individuals may reach the system from external systems or handle organizational information on them, or alternatively requires organization-defined types of external system to be prohibited outright.

Evidence an auditor accepts: Documented terms and conditions or agreements covering permitted external system use; Register of external systems recognised as trusted and the basis for that trust; Policy statement naming external system types that are prohibited
Common gap: Terms exist on paper while unmanaged home devices connect freely in practice
Source framework: NIST SP 800-53 Rev 5
SP 800-53 CM-8 System component inventory

Requires an accurate inventory of system components that covers every component, avoids duplicate or cross system accounting, is held at the granularity needed for tracking and reporting, carries the information the organization has defined for accountability, and is reviewed and updated on a defined frequency.

Evidence an auditor accepts: Component inventory with the defined accountability fields populated; Reconciliation of the inventory against a discovery scan or cloud asset listing; Defined review frequency and evidence of review at that cadence
Common gap: Cloud and container assets absent because inventory is built from a fixed asset register
Source framework: NIST SP 800-53 Rev 5
SP 800-53 CP-8 Telecommunications services

Requires alternate telecommunications services, with the necessary agreements, to allow defined system operations for essential functions to resume within a defined period when primary telecommunications are unavailable at either the primary or the alternate site.

Evidence an auditor accepts: Contracts for alternate telecommunications services with priority and restoration terms; Documentation of the operations they must support and within what period; Evidence of path and carrier diversity from the primary service
Common gap: Second circuit purchased from a different reseller that uses the same physical path
Source framework: NIST SP 800-53 Rev 5
SP 800-53 CP-9 System backup

Requires backups of user-level information, system-level information and system documentation including security and privacy documentation, each at an organization-defined frequency, and requires the confidentiality, integrity and availability of the backup information itself to be protected.

Evidence an auditor accepts: Backup schedule and success reports covering user-level, system-level and documentation backups; Encryption and access control configuration protecting backup data; Restore test records proving backups are usable
Common gap: Documentation and configuration backed up nowhere, only application data
Source framework: NIST SP 800-53 Rev 5
SP 800-53 MP-4 Media storage

Requires organization-defined media types to be physically controlled and securely stored within organization-defined controlled areas, and requires that protection to continue until the media is destroyed or sanitised using approved equipment, techniques and procedures.

Evidence an auditor accepts: Defined controlled areas and the media types stored in each; Physical security evidence for the storage locations; Inventory or custody records for stored media
Common gap: Media awaiting destruction accumulates in unsecured areas for months
Source framework: NIST SP 800-53 Rev 5
SP 800-53 MP-5 Media transport

Requires organization-defined media types to be protected and controlled by defined controls while in transit outside controlled areas, accountability for the media to be maintained throughout, transport activity to be documented, and transport to be carried out only by authorized personnel.

Evidence an auditor accepts: Defined media types in scope for transport and the controls applied, such as encryption or tamper evident containers; Chain of custody records for each transport movement; List of personnel authorized to transport media
Common gap: Backup media couriered with a signature on collection but no custody record in between
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-3 Physical access control

Requires physical access authorizations to be enforced at defined entry and exit points by verifying authorization before entry and controlling ingress and egress with defined mechanisms or guards, physical access audit logs to be kept, publicly accessible areas to be controlled, visitors to be escorted and their activity controlled in defined circumstances,...

Evidence an auditor accepts: Entry and exit point register showing the enforcement mechanism at each; Physical access audit logs from badge or guard systems; Visitor escort procedure and completed visitor logs
Common gap: Tailgating unaddressed, so an authorization check happens for only the first person through
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-18 Location of System Components. Position system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthorized access

Location of System Components. Position system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthorized access

Evidence an auditor accepts: The defined physical and environmental hazards that positioning is intended to mitigate; Floor plans or location documentation showing where system components sit relative to those hazards; Rationale linking each placement decision to the hazard it mitigates and to unauthorised access opportunity
Common gap: Placement driven by available space and cabling, with the hazard rationale written afterwards
Source framework: NIST SP 800-53 Rev 5
SP 800-53 SC-7 Boundary protection

Requires communications to be monitored and controlled at external managed interfaces and at key internal interfaces, publicly accessible components to sit in subnetworks physically or logically separated from internal networks, and connections to external networks or systems to pass only through managed interfaces built from boundary protection devices arra...

Evidence an auditor accepts: Network architecture diagram identifying external and key internal managed interfaces; Firewall and gateway rule sets with review records; Evidence publicly accessible components are separated from internal networks
Common gap: Undocumented external connections such as vendor tunnels bypass the managed interfaces
Source framework: NIST SP 800-53 Rev 5
SP 800-53 SI-7 Software, firmware, and information integrity

Requires integrity verification tools to be employed to detect unauthorized changes to organization-defined software, firmware and information, and requires organization-defined actions to be taken when such unauthorized changes are detected.

Evidence an auditor accepts: Defined list of software, firmware and information subject to integrity verification; Integrity monitoring tool configuration and coverage report; Alerts generated by integrity checks and the response records
Common gap: Integrity monitoring produces constant noise from routine change and is therefore ignored
Source framework: NIST SP 800-53 Rev 5

CIS Controls v8

Attaches to every site: the asset inventory on all of them, anti-malware on the unattended and public ones and on plant, automated and isolated backups where the link is intermittent or absent, remote wipe and the VPN on portable and remote devices.

CIS v8 CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory

Establish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data, to include: end-user devices (including portable and mobile), network devices, non-computing/IoT devices, and servers. Ensure the inventory records the network address (if static), hardware address, machine name, enterp...

Evidence an auditor accepts: Evidence the safeguard is implemented: Establish and Maintain Detailed Enterprise Asset Inventory; Policy/standard covering CIS Control 1 (Inventory and Control of Enterprise Assets); Configuration / tooling output demonstrating the safeguard
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices

Remotely wipe enterprise data from enterprise-owned portable end-user devices when deemed appropriate such as lost or stolen devices, or when an individual no longer supports the enterprise.

Evidence an auditor accepts: Evidence the safeguard is implemented: Enforce Remote Wipe Capability on Portable End-User Devices; Policy/standard covering CIS Control 4 (Secure Configuration of Enterprise Assets and Software); Configuration / tooling output demonstrating the safeguard
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-10.1 Deploy and Maintain Anti-Malware Software

Deploy and maintain anti-malware software on all enterprise assets.

Evidence an auditor accepts: Evidence the safeguard is implemented: Deploy and Maintain Anti-Malware Software; Policy/standard covering CIS Control 10 (Malware Defenses); Configuration / tooling output demonstrating the safeguard
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-11.2 Perform Automated Backups

Perform automated backups of in-scope enterprise assets. Run backups weekly, or more frequently, based on the sensitivity of the data.

Evidence an auditor accepts: Evidence the safeguard is implemented: Perform Automated Backups; Policy/standard covering CIS Control 11 (Data Recovery); Configuration / tooling output demonstrating the safeguard
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data

Establish and maintain an isolated instance of recovery data. Example implementations include, version controlling backup destinations through offline, cloud, or off-site systems or services.

Evidence an auditor accepts: Evidence the safeguard is implemented: Establish and Maintain an Isolated Instance of Recovery Data; Policy/standard covering CIS Control 11 (Data Recovery); Configuration / tooling output demonstrating the safeguard
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure

Require users to authenticate to enterprise-managed VPN and authentication services prior to accessing enterprise resources on end-user devices.

Evidence an auditor accepts: Evidence the safeguard is implemented: Ensure Remote Devices Utilize a VPN and are Connecting to an Enterpris; Policy/standard covering CIS Control 12 (Network Infrastructure Management); Configuration / tooling output demonstrating the safeguard
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8

ISO 22301:2019

Attaches the business continuity plans and procedures to every site, and the plan content and recovery clauses to the sites whose link is intermittent or absent.

ISO 22301 8.4.1 General

Implement and maintain a response structure enabling timely warning and communication to relevant interested parties, with plans and procedures to manage the organization through a disruption and to activate continuity solutions, identified and documented from the output of the selected strategies and solutions, and with procedures that are specific about im...

Evidence an auditor accepts: Documented response structure; Procedures stating immediate steps and the roles that take them; Traceability from selected strategies and solutions to the documented plans
Common gap: Procedures written for one rehearsed scenario, brittle against anything else
Source framework: ISO 22301:2019
ISO 22301 8.4.4 Business continuity plans

Document and maintain business continuity plans that guide teams through response and recovery, collectively containing the actions to continue or recover prioritized activities within predetermined time frames, the means of monitoring the disruption and the response, the pre defined thresholds and process for activating the response, procedures to deliver p...

Evidence an auditor accepts: Plan set with each plan carrying every required element; Activation criteria and thresholds stated in the plan itself; Interdependency and resource sections reconciled to the BIA
Common gap: Plans that cover activation and response but have no stand down, so the organization never formally returns to normal
Source framework: ISO 22301:2019
ISO 22301 8.4.5 Recovery

Maintain documented processes to restore and return business activities from the temporary measures adopted during and after a disruption.

Evidence an auditor accepts: Documented restoration and return to normal processes; Criteria for deciding that temporary measures can be withdrawn; Evidence of use, from exercises or real events, including backlog clearance
Common gap: Recovery treated as implicit once the incident is closed, with no process behind it
Source framework: ISO 22301:2019

The GDPR, Chapter V transfers and Article 32

Attaches Article 32 to every site that holds personal or health data, and Articles 44 to 46 to a site outside the EEA and the United Kingdom that handles personal data of EU or UK persons, read from the home jurisdiction in the preamble and the site's country.

GDPR Art. 32 Security of processing

Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Those measures include,...

Evidence an auditor accepts: The security risk assessment per processing activity, expressed as risk to the rights and freedoms of individuals rather than only as risk to the organisation; Encryption and pseudonymisation coverage at rest, in transit and in backup, with the decision recorded where either was judged not appropriate; Restoration testing results showing personal data was actually recovered inside the intended timeframe, with the date and outcome
Common gap: Risk assessed as impact to the business, so processing that is low risk to the organisation and high risk to individuals attracts weak measures
Source framework: GDPR (Regulation (EU) 2016/679)

DORA, the Digital Operational Resilience Act

Attaches Article 11 (response and recovery) to every site of a financial entity and Article 12 (backup, restoration and recovery) to the sites whose link is intermittent or absent; a site with no recovery objective is a finding.

DORA Art. 11 Response and recovery

Financial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.

Evidence an auditor accepts: ICT business continuity policy + response/recovery plans; Records of plan testing
Common gap: No ICT continuity/response/recovery plans
Source framework: DORA (Regulation (EU) 2022/2554)
DORA Art. 12 Backup policies and procedures, restoration and recovery

Financial entities shall develop and document backup policies and procedures, and restoration and recovery procedures and methods, ensuring backups can be restored with minimal disruption, with backup systems physically and logically segregated from the source system.

Evidence an auditor accepts: Backup and restoration policies/procedures; Evidence of segregated backups and restoration tests
Common gap: No tested backups
Source framework: DORA (Regulation (EU) 2022/2554)

NIST SP 800-82 Rev 3, the OT overlay

Attaches to the sites that run plant: zones and conduits and the dispersed-OT guidance on every one, tamper detection where nobody is there, spares and cold standby where the link is intermittent, and the two remote-access controls where remote access is named. IEC 62443 is named beside it as a reference; its text is not quoted.

SP 800-82 OT-ARCH-1 Network Segmentation by Zones and Conduits

Segment OT networks into logical zones and conduits aligned with the Purdue model and IEC 62443, restricting traffic between zones via controlled conduits with documented data flows.

Evidence an auditor accepts: Zone and conduit diagram; Purdue level mapping; Conduit data flow matrix
Common gap: Flat OT network
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-PHYS-3 Tamper Detection and Response

Detect and respond to tampering of OT devices, cabinets, and network equipment through seals, sensors, alarms, and inspection procedures.

Evidence an auditor accepts: Tamper seal logs; Cabinet door alarm records; Inspection schedule and findings
Common gap: No tamper seals
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-REC-3 Spare Parts and Cold Standby

Maintain spare PLCs, switches, servers, and media required for rapid replacement of failed or compromised OT components, with documented locations and integrity controls.

Evidence an auditor accepts: Spare parts inventory; Storage location records; Periodic test of cold spares
Common gap: Critical spares unavailable
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-SECTOR-3 Distributed and Geographically Dispersed OT

Address security for geographically distributed OT (substations, pump stations, wellheads, remote terminal units) where physical access controls and connectivity options are constrained.

Evidence an auditor accepts: Remote site security standard; Communications security configuration (encrypted radio, cellular VPN); Site inspection records
Common gap: Unencrypted SCADA communications
Source framework: NIST SP 800-82 Rev 3

NIST SP 800-207, zero trust architecture

Attaches the satellite-facility deployment scenario to every site and the two design tenets (every communication secured, every asset's posture monitored) to the sites where remote access is named. No regime page: it renders on the remote-access rows and the finding.

SP 800-207 SC-SATELLITE Deployment Scenario: Enterprise with Satellite Facilities

Applies ZTA to an organization with a headquarters plus geographically dispersed locations and remote workers that have no full enterprise-owned network.

Evidence an auditor accepts: ZTA design for remote workers and satellite sites; Policy coverage for off-network access
Common gap: VPN-only model treated as zero trust
Source framework: NIST SP 800-207

Questions for the hardware vendor

six, and one for the class

For the process control and safety systems, the drilling systems and the crew PCs, over an intermittent link:

  1. Can you show measured boot or firmware attestation on the equipment, and how a failed check reports back over an intermittent link?
  2. How does the equipment take an update unattended over an intermittent link, and how does it roll back on its own when the update fails part way?
  3. Can a lost or stolen unit be wiped remotely, and what happens to the wipe command while the unit is offline?
  4. Is local storage on the equipment encrypted at rest with the key held off the device, and can that be verified from the fleet console?
  5. Can the equipment be recovered to a known state by a non-technical person on site, without a technician's visit?
  6. What spares, lead times and end-of-support dates apply to the equipment, and who holds the spares nearest the site?

For this class: How is the process-control network kept apart from the crew and satellite networks, and how are control updates staged and rolled back offshore?

Findings this class can raise

Do this for every site on your list

Paste the list and get this reading for every site at once, with the link, the exposure, the data held, the findings and the duty rows per regime. Eight sites free, no account.

Build my edge register

Mine, quarry and camp · Research and monitoring station