Overview / Objectives
Define an enterprise policy that reduces attack surface, enables measurable risk management, and provides practical controls for legacy or constrained OT/IoT in manufacturing.
Asset Identification & Inventory
- Mandatory CMDB with automated discovery (NMAP, passive network sensors, IoT/OT-aware scanners) plus manual verification.
- Record: device type, model, firmware, serial, owner, location, network zone, risk rating, business function, maintenance window, cryptographic identity (cert thumbprint).
- Reconcile weekly; quarterly audit with plant engineers.
Network Segmentation
- Zone model: Corporate IT | DMZ | OT Perimeter | OT Cell/Cellular (per production line) | Safety-Critical.
- Enforce with VLANs, industrial protocol-aware firewalls, flow whitelisting, and strictly defined cross-zone ACLs.
- Microsegmentation for high-risk devices using host-based controls or network tags; east-west controls via industrial proxies/gateways.
Patching Cadence & Vulnerability Management
- Risk-based cadence: safety-critical devices → emergency patch window; production-critical → scheduled monthly/quarterly windows; non-critical → standard monthly.
- Vulnerability assessment weekly; apply virtual patching via network controls when vendor patch unavailable.
- SLAs: patch assessment within 7 days of CVE; mitigation or patch within 30/90/180 days based on risk tier.
- Change control with maintenance windows and test staging.
Secure Provisioning
- Device identity via X.509 certificates issued from enterprise PKI or hardware root-of-trust (TPM/SE) when available.
- Zero-touch provisioning workflow for new devices: secure onboarding VLAN → attest firmware hash → issue certs → move to operational zone.
- Use configuration baselines, least-privilege service accounts, disable unused interfaces/protocols.
Remote Access
- Prohibit direct vendor/remote access across OT zones. Use managed jump hosts/bastion in DMZ with:
- MFA, timeboxed access, just-in-time session approval, session recording/keystroke logging.
- Vendor accounts scoped and ephemeral; audit trails forwarded to SIEM.
- VPN only to jump host, not to OT devices.
Devices with Limited Update Capabilities
- Classify as Unpatchable; apply compensating controls:
- Strict network isolation, application/protocol whitelisting, read-only mirrors where practical.
- Inline protocol gateways that sanitize/translate traffic; deny unknown commands.
- Use virtual patching (IPS signatures), allowlisting, and strict monitoring (IDS tuned for industrial protocols).
- Plan device replacement in asset lifecycle policy; risk-acceptance documented and reviewed annually.
Monitoring, Logging & Incident Response
- Centralized logging for OT-specific telemetry and flow logs to SIEM; behavioral analytics for protocol anomalies.
- Playbooks for containment, forensics, and safe shutdown that include OT SMEs.
- KPIs: patch SLA compliance, number of unpatched critical CVEs, mean time to detect/contain.
Governance & Exceptions
- Policy ownership by Security Architecture + OT Engineering. Exceptions require documented risk assessment, compensating controls, and quarterly reapproval.
- Annual tabletop exercises and continuous training for operations and vendors.
This policy balances operational continuity with defense-in-depth, using identity, segmentation, compensating controls, and monitored remote access to protect legacy and modern IoT/OT assets.