Pumping station and treatment works
A PLC or RTU, a local HMI, level and flow instruments, a dosing controller and a telemetry outstation, in a small building on the edge of town.
How the register reads it
| Also called | treatment works, booster station, telemetry outstation |
|---|---|
| Family | Plant, substation and utility asset |
| Exposure by default | Unattended: visited on a round; unstaffed otherwise, with the door the only control. A line that says attended, unattended, public or hostile (outdoors, in transit, at sea) overrides it. |
| Link by default | Intermittent: telemetry over radio or cellular, polled rather than continuous. A line that names the link (fibre, 4G, satellite, radio, offline) overrides it. |
| Regulated data by default | None; a line that names customer, staff, patient, card or controlled data adds it. |
| Runs plant | Yes: the OT overlay (NIST SP 800-82 Rev 3) attaches, and IEC 62443 is named beside it as a reference. |
| What a loss costs | A works cut off runs on its last setpoints; a dosing controller reached from outside changes what goes into the water. |
| Contract focus | Telemetry service levels, controller firmware terms, dosing-system safety interlocks, spares held by the operator. |
What each regime attaches
33 clauses across 7 regimes, on the class defaultsShown on a register for the regimes you tick, by the exposure, link, data and plant the line states; with none ticked, the ISO 27001 rows are the default. Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27001:2022, with the 27002:2022 guidance beside it
Attaches to every site: the off-premises, equipment, media, endpoint, backup, redundancy, network and continuity controls of Annex A, by the site's exposure, link, data and plant. With nothing ticked these rows render as the default.
ISO 27001 5.30 ICT readiness for business continuityPlan, implement, maintain and test ICT readiness against business continuity objectives.
ISO 27002 5.30 guidance: Requires ICT readiness to be planned, implemented, maintained and tested against business continuity objectives and ICT continuity requirements. Supporting material frames this as ICT infrastructure and resources being resilient enough to carry business operations through disruption.
Common gap: Testing frequency not aligned with risk
Source framework: ISO/IEC 27001:2022
ISO 27001 7.4 Physical security monitoringContinuously monitor premises for unauthorized physical access.
ISO 27002 7.4 guidance: Requires premises to be monitored continuously for unauthorised physical access. Supporting material frames this as continuous monitoring of physical security controls so that unauthorised entry and other physical security incidents are detected and responded to.
Common gap: logs not retained for required period
Source framework: ISO/IEC 27001:2022
ISO 27001 7.8 Equipment siting and protectionSite equipment securely and protect it.
ISO 27002 7.8 guidance: Requires equipment to be sited securely and protected. Older source material in the folder expands this as siting equipment to reduce unnecessary access into work areas, positioning and restricting the viewing angle of facilities handling sensitive data, isolating items needing special protection, and guarding against physical hazards such as theft, fire, water, dust, vibration, electrical interference and vandalism.
Common gap: Assuming perimeter security covers equipment
Source framework: ISO/IEC 27001:2022
ISO 27001 7.9 Security of assets off-premisesProtect assets used or held off-site.
ISO 27002 7.9 guidance: Requires assets located away from the organisation's premises to be protected.
Common gap: Missing offsite asset register
Source framework: ISO/IEC 27001:2022
ISO 27001 7.13 Equipment maintenanceMaintain equipment correctly to preserve availability, integrity and confidentiality.
ISO 27002 7.13 guidance: Requires equipment to be maintained correctly, so that information stays available, intact and confidential.
Common gap: no documented maintenance schedule
Source framework: ISO/IEC 27001:2022
ISO 27001 8.7 Protection against malwareImplement malware protection backed by user awareness.
ISO 27002 8.7 guidance: Requires malware protection to be put in place and reinforced by suitable awareness among users.
Common gap: Outdated malware signatures not regularly updated
Source framework: ISO/IEC 27001:2022
ISO 27001 8.9 Configuration managementEstablish, document, implement, monitor and review secure configurations for hardware, software, services and networks.
ISO 27002 8.9 guidance: Requires configurations of hardware, software, services and networks, including their security configurations, to be established, documented, implemented, monitored and reviewed. Supporting material frames this as a standing process that keeps systems configured securely and consistently.
Common gap: outdated baselines
Source framework: ISO/IEC 27001:2022
ISO 27001 8.13 Information backupMaintain and regularly test backups of information, software and systems per the backup policy.
ISO 27002 8.13 guidance: Requires backup copies of information, software and systems to be maintained and regularly tested, in line with the agreed topic specific policy on backup. Supporting SME guidance treats regular creation of backups together with tested recovery as the substance of the control, not the copy on its own.
Common gap: infrequent restore testing
Source framework: ISO/IEC 27001:2022
ISO 27001 8.14 Redundancy of information processing facilitiesBuild enough redundancy into processing facilities to meet availability requirements.
ISO 27002 8.14 guidance: Requires information processing facilities to be implemented with redundancy sufficient to meet the availability requirements placed on them.
Common gap: reliance on undocumented manual backups
Source framework: ISO/IEC 27001:2022
ISO 27001 8.20 Networks securitySecure, manage and control networks and network devices.
ISO 27002 8.20 guidance: Requires networks and network devices to be secured, managed and controlled in order to protect the information carried in systems and applications.
Common gap: outdated topology diagrams
Source framework: ISO/IEC 27001:2022
ISO 27001 8.22 Segregation of networksSegregate groups of services, users and systems in the network.
ISO 27002 8.22 guidance: Requires segregation within the organisation's networks, keeping groups of information services, of users and of systems apart from one another.
Common gap: Informal or outdated network maps used instead of documented diagrams
Source framework: ISO/IEC 27001:2022
NIST SP 800-53 Rev 5
Attaches to every site: the PE family for the premises and the alternate work site, MP for the media, AC-17, AC-19 and AC-20 for remote access, mobile devices and external systems, the CP family for the sites that lose their link, SC-7 for the boundary and SI-7 and CM-8 for what runs there.
SP 800-53 CM-8 System component inventoryRequires an accurate inventory of system components that covers every component, avoids duplicate or cross system accounting, is held at the granularity needed for tracking and reporting, carries the information the organization has defined for accountability, and is reviewed and updated on a defined frequency.
Common gap: Cloud and container assets absent because inventory is built from a fixed asset register
Source framework: NIST SP 800-53 Rev 5
SP 800-53 CP-8 Telecommunications servicesRequires alternate telecommunications services, with the necessary agreements, to allow defined system operations for essential functions to resume within a defined period when primary telecommunications are unavailable at either the primary or the alternate site.
Common gap: Second circuit purchased from a different reseller that uses the same physical path
Source framework: NIST SP 800-53 Rev 5
SP 800-53 CP-9 System backupRequires backups of user-level information, system-level information and system documentation including security and privacy documentation, each at an organization-defined frequency, and requires the confidentiality, integrity and availability of the backup information itself to be protected.
Common gap: Documentation and configuration backed up nowhere, only application data
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-3 Physical access controlRequires physical access authorizations to be enforced at defined entry and exit points by verifying authorization before entry and controlling ingress and egress with defined mechanisms or guards, physical access audit logs to be kept, publicly accessible areas to be controlled, visitors to be escorted and their activity controlled in defined circumstances,...
Common gap: Tailgating unaddressed, so an authorization check happens for only the first person through
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-6 Monitoring physical accessRequires physical access to the facility to be monitored so that physical security incidents are detected and responded to, physical access logs to be reviewed at a defined frequency and on defined events, and review and investigation results to be coordinated with the incident response capability.
Common gap: Surveillance recorded but never reviewed unless something is already known to be wrong
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-18 Location of System Components. Position system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthorized accessLocation of System Components. Position system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthorized access
Common gap: Placement driven by available space and cabling, with the hazard rationale written afterwards
Source framework: NIST SP 800-53 Rev 5
SP 800-53 SC-7 Boundary protectionRequires communications to be monitored and controlled at external managed interfaces and at key internal interfaces, publicly accessible components to sit in subnetworks physically or logically separated from internal networks, and connections to external networks or systems to pass only through managed interfaces built from boundary protection devices arra...
Common gap: Undocumented external connections such as vendor tunnels bypass the managed interfaces
Source framework: NIST SP 800-53 Rev 5
SP 800-53 SI-7 Software, firmware, and information integrityRequires integrity verification tools to be employed to detect unauthorized changes to organization-defined software, firmware and information, and requires organization-defined actions to be taken when such unauthorized changes are detected.
Common gap: Integrity monitoring produces constant noise from routine change and is therefore ignored
Source framework: NIST SP 800-53 Rev 5
CIS Controls v8
Attaches to every site: the asset inventory on all of them, anti-malware on the unattended and public ones and on plant, automated and isolated backups where the link is intermittent or absent, remote wipe and the VPN on portable and remote devices.
CIS v8 CIS-1.1 Establish and Maintain Detailed Enterprise Asset InventoryEstablish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data, to include: end-user devices (including portable and mobile), network devices, non-computing/IoT devices, and servers. Ensure the inventory records the network address (if static), hardware address, machine name, enterp...
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-10.1 Deploy and Maintain Anti-Malware SoftwareDeploy and maintain anti-malware software on all enterprise assets.
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-11.2 Perform Automated BackupsPerform automated backups of in-scope enterprise assets. Run backups weekly, or more frequently, based on the sensitivity of the data.
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-11.4 Establish and Maintain an Isolated Instance of Recovery DataEstablish and maintain an isolated instance of recovery data. Example implementations include, version controlling backup destinations through offline, cloud, or off-site systems or services.
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
ISO 22301:2019
Attaches the business continuity plans and procedures to every site, and the plan content and recovery clauses to the sites whose link is intermittent or absent.
ISO 22301 8.4.1 GeneralImplement and maintain a response structure enabling timely warning and communication to relevant interested parties, with plans and procedures to manage the organization through a disruption and to activate continuity solutions, identified and documented from the output of the selected strategies and solutions, and with procedures that are specific about im...
Common gap: Procedures written for one rehearsed scenario, brittle against anything else
Source framework: ISO 22301:2019
ISO 22301 8.4.4 Business continuity plansDocument and maintain business continuity plans that guide teams through response and recovery, collectively containing the actions to continue or recover prioritized activities within predetermined time frames, the means of monitoring the disruption and the response, the pre defined thresholds and process for activating the response, procedures to deliver p...
Common gap: Plans that cover activation and response but have no stand down, so the organization never formally returns to normal
Source framework: ISO 22301:2019
ISO 22301 8.4.5 RecoveryMaintain documented processes to restore and return business activities from the temporary measures adopted during and after a disruption.
Common gap: Recovery treated as implicit once the incident is closed, with no process behind it
Source framework: ISO 22301:2019
DORA, the Digital Operational Resilience Act
Attaches Article 11 (response and recovery) to every site of a financial entity and Article 12 (backup, restoration and recovery) to the sites whose link is intermittent or absent; a site with no recovery objective is a finding.
DORA Art. 11 Response and recoveryFinancial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.
Common gap: No ICT continuity/response/recovery plans
Source framework: DORA (Regulation (EU) 2022/2554)
DORA Art. 12 Backup policies and procedures, restoration and recoveryFinancial entities shall develop and document backup policies and procedures, and restoration and recovery procedures and methods, ensuring backups can be restored with minimal disruption, with backup systems physically and logically segregated from the source system.
Common gap: No tested backups
Source framework: DORA (Regulation (EU) 2022/2554)
NIST SP 800-82 Rev 3, the OT overlay
Attaches to the sites that run plant: zones and conduits and the dispersed-OT guidance on every one, tamper detection where nobody is there, spares and cold standby where the link is intermittent, and the two remote-access controls where remote access is named. IEC 62443 is named beside it as a reference; its text is not quoted.
SP 800-82 OT-ARCH-1 Network Segmentation by Zones and ConduitsSegment OT networks into logical zones and conduits aligned with the Purdue model and IEC 62443, restricting traffic between zones via controlled conduits with documented data flows.
Common gap: Flat OT network
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-PHYS-3 Tamper Detection and ResponseDetect and respond to tampering of OT devices, cabinets, and network equipment through seals, sensors, alarms, and inspection procedures.
Common gap: No tamper seals
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-REC-3 Spare Parts and Cold StandbyMaintain spare PLCs, switches, servers, and media required for rapid replacement of failed or compromised OT components, with documented locations and integrity controls.
Common gap: Critical spares unavailable
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-SECTOR-3 Distributed and Geographically Dispersed OTAddress security for geographically distributed OT (substations, pump stations, wellheads, remote terminal units) where physical access controls and connectivity options are constrained.
Common gap: Unencrypted SCADA communications
Source framework: NIST SP 800-82 Rev 3
NIST SP 800-207, zero trust architecture
Attaches the satellite-facility deployment scenario to every site and the two design tenets (every communication secured, every asset's posture monitored) to the sites where remote access is named. No regime page: it renders on the remote-access rows and the finding.
SP 800-207 SC-SATELLITE Deployment Scenario: Enterprise with Satellite FacilitiesApplies ZTA to an organization with a headquarters plus geographically dispersed locations and remote workers that have no full enterprise-owned network.
Common gap: VPN-only model treated as zero trust
Source framework: NIST SP 800-207
Questions for the hardware vendor
six, and one for the classFor the PLC or RTU, the HMI and the dosing controller, over an intermittent link:
- Can you show measured boot or firmware attestation on the equipment, and how a failed check reports back over an intermittent link?
- How does the equipment take an update unattended over an intermittent link, and how does it roll back on its own when the update fails part way?
- Can a lost or stolen unit be wiped remotely, and what happens to the wipe command while the unit is offline?
- Is local storage on the equipment encrypted at rest with the key held off the device, and can that be verified from the fleet console?
- Can the equipment be recovered to a known state by a non-technical person on site, without a technician's visit?
- What spares, lead times and end-of-support dates apply to the equipment, and who holds the spares nearest the site?
For this class: Which setpoints can be changed remotely, by whom, and how is a change recorded when the site is not polled?
Findings this class can raise
- Intermittent or no link, and no backup stated
A site whose link comes and goes, or that has none, keeps its records locally until it can sync; if the line says nothing about a backup, the register cannot tell whether that local copy is the only one. The continuity duties ask for the backup, the restore and the plan for the period the site is on its own. - Plant with no segregation stated
A site that runs plant (controllers, RTUs, HMIs, historians) where the line says nothing about a segregated network, a zone or a firewall between the plant and everything else. The OT guidance and the network controls ask for the zones and the conduits to be drawn and the boundary enforced; the register cannot see them, so it asks. - Remote access to plant
A site that runs plant where the line names remote access: a vendor's maintenance session, the engineers' dial-in, a support path. The OT guidance treats remote access to control systems as its own duty, with the vendor's access under separate conditions, and the zero-trust design rules ask that every session be authenticated and every device's posture checked before it reaches the controller. - Concentration in one class or one link type
One site class holding a third or more of the sites (three or more of them), or a single link type across every site: the register names the share so the dependence is a recorded one. A failure mode shared by every site (one carrier, one device model, one class) is what the continuity and redundancy duties ask to be planned for, not avoided. - Financial entity site with no recovery objective
DORA is ticked and the line carries no recovery time objective. Articles 11 and 12 ask a financial entity to hold response and recovery plans and backup and restoration procedures with recovery objectives for its ICT systems, wherever they run; a branch, an ATM estate or an outsourcing site without one is a gap in the plan, not in the site. - Hardware questions unanswered
On the first paste no line answers the six questions the register puts to the vendor of the hardware at each site: attestation of firmware and boot, unattended update and rollback, remote wipe, local storage encryption, recovery without a technician, spares; each class adds one question of its own. The finding is the RFI page: the questions per site, grouped by class, ready to paste into the next rollout's request.
Do this for every site on your list
Paste the list and get this reading for every site at once, with the link, the exposure, the data held, the findings and the duty rows per regime. Eight sites free, no account.
Build my edge register