PROGRAM-1a — Cybersecurity Program Strategy
Section 6.10, Cybersecurity Program Management (PROGRAM), Objective 1
Relevant requirement: The organization has a cybersecurity program strategy, which may be developed and managed in an ad hoc manner.
Reference details and direct document links for establishing operational OT/ICS cybersecurity policies that address safety, availability, regulatory requirements, technical constraints, legacy-system exceptions, and OT-specific incident response.
Establish OT/ICS specific cybersecurity policies (operational). Enterprise or IT policies are common, but they often do not address the safety, availability, regulatory, technical, and incident-response requirements of OT systems.
Section 6.10, Cybersecurity Program Management (PROGRAM), Objective 1
Relevant requirement: The organization has a cybersecurity program strategy, which may be developed and managed in an ad hoc manner.
Appendix A, CSF Core, GOVERN Function
Relevant requirement: Organizational cybersecurity policy is established, communicated, and enforced; policy is reviewed and updated as requirements, threats, technology, and mission change.
Program Management control family
Relevant requirement: Develop, disseminate, review, update, and protect an organization-wide information security program plan that identifies roles, responsibilities, management commitment, coordination, and compliance.
Section 3.3, Development and Deployment of an OT Cybersecurity Program
Relevant requirement: OT governance should include policies, procedures, and processes for managing regulatory, legal, risk, environmental, and operational requirements, with assigned responsibilities and accountability.