Industrial Control Systems Security Assessment Questionnaire
General Information
Organization Name
Contact Person
Email
System Overview
Type of Industrial Control Systems in Use
Brief Description of System Architecture
Asset Inventory
Does your organization maintain an up-to-date inventory of ICS assets?
Yes
No
If yes, please describe the process:
Network Security
Are your ICS networks segmented from corporate IT networks?
Yes
No
Is remote access to ICS systems allowed?
Yes
No
If yes, please specify the security controls applied:
Access Control
Is multi-factor authentication required for access to ICS systems?
Yes
No
Describe user account management practices for ICS personnel:
Patch Management
Does your organization have a formal patch management policy for ICS?
Yes
No
How frequently are patches applied to ICS components?
Incident Response
Is there an incident response plan specific to ICS?
Yes
No
How often is the incident response plan tested?
Additional Comments
Provide any additional information relevant to ICS security at your organization: