Creating compliance ICS checklist security assessment
Budget: $250 – $750 USD
Preparing a security assessment that will combine 5
different security standards related to Information
Security, Industry Control Systems, and the convergence
between them to be presented into one excel checklist
sheet that will be used to review compliance with an
objective of evaluating and mitigating risks in various
types of organizations,
Standards
Name of Standards:
1) Local Governing Authority (Standard pdf. Available, you
are required to convert it to excel assessment sheet)
List of Standards falling user the purview of Local
Governing Authority. Will be provided by my end
2) NESA - National Electronic Security Authority (excel
checklist available & I will be providing it)
UAE-NESA
3) NIST - National Institute of Standards & Technology
(NIST SP 800-53 R5 & NIST SP
800-82 R2 available, you are required to convert it to excel
assessment sheet)
4) International Electrotechnical Commission (IEC-62443
series, you are required to
convert it to excel assessment sheet, and provide the pdf.
document for verification and ensure )
the IEC needs to be obtained by you.
5) ISO 27001 (excel checklist available & will be provided)
combine the requirements of the above checklist with ISO
checklist/ standards 27001:1 and 27001:2
All these standards needs to have the specific reference All these standards needs to have the specific reference line, page, chapter etc
Main Framework
The checklist will start with ISO 27001 to evaluate the
structure and framework of the respective organization
a.27001:1
b.27001:2
Standards applicable for ICS only:
a) IEC-62443 series b) NIST
c) Local Government Authority Standard
Standards applicable for both ICS & IS:
• NESA standard -UAE NESA
Any other standard that can be compatible for both IS
and ICS can be added Standard applicable for
Information Security only:
• NESA Standard will be used for clients seeking
Information Security compliance assessments
Note: Recommendation of using another suitable ISO
framework for the project can be
discussed ex: 9001:2015- NA
All the compiled standards needs to have the ability to be
filtered on the workbook directly based on the application
above
This will only be a checklist for the assessment for the industrial control systems and Internet security compliance
This checklist will be used by various individuals, the 1- on field auditor
2- report creator
different security standards related to Information
Security, Industry Control Systems, and the convergence
between them to be presented into one excel checklist
sheet that will be used to review compliance with an
objective of evaluating and mitigating risks in various
types of organizations,
Standards
Name of Standards:
1) Local Governing Authority (Standard pdf. Available, you
are required to convert it to excel assessment sheet)
List of Standards falling user the purview of Local
Governing Authority. Will be provided by my end
2) NESA - National Electronic Security Authority (excel
checklist available & I will be providing it)
UAE-NESA
3) NIST - National Institute of Standards & Technology
(NIST SP 800-53 R5 & NIST SP
800-82 R2 available, you are required to convert it to excel
assessment sheet)
4) International Electrotechnical Commission (IEC-62443
series, you are required to
convert it to excel assessment sheet, and provide the pdf.
document for verification and ensure )
the IEC needs to be obtained by you.
5) ISO 27001 (excel checklist available & will be provided)
combine the requirements of the above checklist with ISO
checklist/ standards 27001:1 and 27001:2
All these standards needs to have the specific reference All these standards needs to have the specific reference line, page, chapter etc
Main Framework
The checklist will start with ISO 27001 to evaluate the
structure and framework of the respective organization
a.27001:1
b.27001:2
Standards applicable for ICS only:
a) IEC-62443 series b) NIST
c) Local Government Authority Standard
Standards applicable for both ICS & IS:
• NESA standard -UAE NESA
Any other standard that can be compatible for both IS
and ICS can be added Standard applicable for
Information Security only:
• NESA Standard will be used for clients seeking
Information Security compliance assessments
Note: Recommendation of using another suitable ISO
framework for the project can be
discussed ex: 9001:2015- NA
All the compiled standards needs to have the ability to be
filtered on the workbook directly based on the application
above
This will only be a checklist for the assessment for the industrial control systems and Internet security compliance
This checklist will be used by various individuals, the 1- on field auditor
2- report creator