|
6.2.1
|
ISMS |
Yes
|
|
6.2.2
|
Background Checks |
Minor
|
|
6.2.3
|
Roles & Responsibilities |
Major
|
|
6.2.4
|
Awareness Training |
No
|
|
6.2.5
|
Responsibility Training |
N/A
|
|
6.2.6
|
Supply Chain Security |
Yes
|
|
6.3.1
|
Security Risk Mitigation |
Yes
|
|
6.3.2
|
Processes For Discovery Of Security Anomalies |
No
|
|
6.3.3
|
Secure Development And Support |
No
|
|
6.3.4
|
SP Review |
No
|
|
7.2.1
|
Asset Inventory Baseline |
No
|
|
7.2.2
|
Infrastructure Documentation |
No
|
|
7.2.3
|
Configuration Settings |
No
|
|
7.2.4
|
Change Control |
No
|
|
8.2.1
|
Segmentation from non-IACS zones |
No
|
|
8.2.2
|
Documentation of zones and network zone interconnections |
No
|
|
8.2.3
|
Network segmentation from safety systems |
No
|
|
8.2.4
|
Network Autonomy |
Yes
|
|
8.2.5
|
Network Disconnection from external networks |
No
|
|
8.2.6
|
Internal Network Access Control |
No
|
|
8.2.7
|
Network accessible services |
No
|
|
8.2.8
|
User Messaging |
No
|
|
8.2.9
|
Network Time Distribution |
No
|
|
8.3.1
|
Wireless Protocols |
No
|
|
8.3.2
|
Wireless Network Segmentation |
No
|
|
8.3.3
|
Wireless Properties and Addresses |
No
|
|
8.4.1
|
Remote Access Applications |
No
|
|
8.4.2
|
Remote Access Connections |
No
|
|
8.4.3
|
Remote Access Termination |
No
|
|
9.2.1
|
Component Hardening |
No
|
|
9.2.2
|
Dedicated Portable Media |
No
|
|
9.3.1
|
Malware Free |
No
|
|
9.3.2
|
Malware Protection |
No
|
|
9.3.3
|
Malware protection software validation and installation |
No
|
|
9.4.1
|
Security patch authenticity/integrity |
No
|
|
9.4.2
|
Security patch validation and installation |
No
|
|
9.4.3
|
Security patch status |
No
|
|
9.4.4
|
Security patching retention of security |
No
|
|
9.4.5
|
Security patch mitigation |
No
|
|
10.2.1
|
Data Classification |
No
|
|
10.2.2
|
Data Confidentiality |
No
|
|
10.2.3
|
Safety system configuration mode |
No
|
|
10.2.4
|
Data Retention Policy |
No
|
|
10.2.5
|
Cryptographic mechanisms |
No
|
|
10.2.6
|
Key Management |
No
|
|
10.2.7
|
Data Integrity |
No
|
|
11.2.1
|
User Identity Assignment |
No
|
|
11.2.2
|
User Identity Removal |
No
|
|
11.2.3
|
Identity Persistence |
No
|
|
11.2.4
|
Access Rights Assignments |
No
|
|
11.2.5
|
Least Privilege |
No
|
|
11.2.6
|
Software service authentication |
No
|
|
11.2.7
|
Software services interactive login rights |
No
|
|
11.2.8
|
Human User Authentication |
No
|
|
11.2.9
|
Multifactor authentication (MFA) |
No
|
|
11.2.10
|
Mutual Authentication |
No
|
|
11.2.11
|
Password Protection |
No
|
|
11.2.12
|
Shared and disclosed/compromised passwords |
No
|
|
11.2.13
|
User login display information |
No
|
|
11.2.14
|
User login failure displays |
No
|
|
11.2.15
|
Consecutive login failures |
No
|
|
11.2.16
|
Session Integrity |
No
|
|
11.2.17
|
Concurrent Sessions |
No
|
|
11.2.18
|
Screen Lock |
No
|
|
11.2.19
|
Component Authentication |
No
|
|
11.3.1
|
Authorization |
No
|
|
11.3.2
|
Separation of Duties |
No
|
|
11.3.3
|
Multiple Approval |
No
|
|
11.3.4
|
Manual elevation of privileges |
No
|
|
12.2.1
|
Event Detection |
No
|
|
12.2.2
|
Event Reporting |
No
|
|
12.2.3
|
Event Reporting Interfaces |
No
|
|
12.2.4
|
Logging |
No
|
|
12.2.5
|
Log Entries |
No
|
|
12.2.6
|
Log Access |
No
|
|
12.2.7
|
Event Analysis |
No
|
|
12.2.8
|
Incident Handling and Response |
No
|
|
12.2.9
|
Vulnerability Handling |
No
|
|
13.2.1
|
Continuity Management |
No
|
|
13.2.2
|
Resource Availability Management |
No
|
|
13.2.3
|
Failure State |
No
|
|
13.3.1
|
Backup |
No
|
|
13.3.2
|
Backup Non-Interference |
No
|
|
13.3.3
|
Backup Verification |
No
|
|
13.3.4
|
Backup Media |
No
|
|
13.3.5
|
Backup Restoration |
No
|