ISO 27001 when OT is in scope
ISO/IEC 27001 is the international standard for information security management systems (ISMS). It is not mandatory, but many industrial organisations already hold certification because of customer or group requirements. The question is whether your plant is genuinely within scope.
ISO 27001 structures security as a management system: context and risks, policy and objectives, a set of controls (Annex A) and a continual improvement cycle. It is general-purpose—it works for a bank or a factory—which is both its strength and its limitation: it provides governance and traceability, but does not address the detail of a PLC or an industrial protocol.
The usual problem is not having the certificate, but its scope. In many certifications, the ISMS covers offices and the data centre, while the control network is excluded “because it is something else”. When NIS2 arrives or a customer asks about the plant, that gap becomes apparent. Our work typically consists of extending the ISMS scope to OT and translating each Annex A control into what it means for a control system, using IEC 62443 for the technical detail.
| Requirement | What it means in OT |
|---|---|
| Clauses 4–6 — Context, leadership and risks | The ISMS scope must explicitly include the control network, and its risk analysis must include impact on the physical process. An ISMS that stops at the office leaves the plant uncovered. |
| A.5 — Policies and organisation | Policies that explicitly name control systems and assign responsibilities across IT and OT, rather than a generic “information systems” procedure. |
| A.5.9 / A.5.10 — Inventory and acceptable use of assets | The asset inventory must extend to controllers, HMIs and third-party equipment. It is precisely what almost no plant has, and where everything begins. |
| A.5.15–A.5.18 — Access control | Named accounts, least privilege and MFA for integrator remote access and remote-control systems too; a shared maintenance account will not pass an audit. |
| A.5.19–A.5.22 — Suppliers and supply chain | Integrators and manufacturers with access to the plant are within scope: you must govern who connects, with which permissions and under which contract. |
| A.5.23 — Cloud services | Historians, cloud SCADA or remote maintenance: industrial data sent to a third party needs the same assurances as corporate data. |
| A.5.24–A.5.28 — Incident management | An incident process that accounts for process constraints: what can and cannot be isolated in OT, and how evidence is preserved. |
| A.5.29 / A.5.30 — ICT continuity and recovery | Continuity that includes configuration backups for control equipment and tested restoration, not just ERP recovery. |
| A.8 — Technological controls | Hardening, vulnerability management, logging and monitoring, malware protection and network security applied to OT with its availability and safety constraints. |
| Certification and audit | Audit by an accredited body and a continual improvement cycle. Extending scope to OT makes the certificate tell the truth about the plant, not only the offices. |
ISO 27001 provides the governance framework; our services provide the technical detail and evidence:
- OT cybersecurity strategy — aligns the ISMS with a realistic roadmap for the industrial environment.
- OT assessment — the plant inventory and risk analysis assumed by the ISMS.
- Managed inventory — Annex A inventory and vulnerability controls, with continuous evidence.
- IEC 62443 — the technical detail ISO 27001 does not provide for control systems.