OT/ICS Standards Reference

Ensure OT/ICS roles offshore are defined and documented.

Reference details and direct document links for documenting OT/ICS cybersecurity roles, responsibilities, authorities, and accountability across operations, supply chain, vendors, and key onshore/offshore personnel.

3

Control / Question

Ensure OT/ICS roles offshore are defined and documented. Roles should cover operations, supply chain, vendors, support personnel, and other key stakeholders involved in OT/ICS cybersecurity execution or decision-making.

C2M2 PROGRAM-1e (MIL2) NIST CSF 2.0 GV.RR NIST SP 800-53 PM-1 NIST SP 800-82r3 §3.3.1
DOE C2M2 v2.1

PROGRAM-1e — Program Structure and Organization

Section 6.10, Cybersecurity Program Management (PROGRAM), Objective 1

Relevant requirement: The cybersecurity program strategy defines the structure and organization of the cybersecurity program.

Use this to require a documented OT/ICS program structure that identifies who owns, supports, approves, and executes cybersecurity activities across operations, engineering, supply chain, vendors, and management.
NIST Cybersecurity Framework 2.0

GV.RR — Roles, Responsibilities, and Authorities

Appendix A, CSF Core, GOVERN Function

Relevant requirement: Cybersecurity roles, responsibilities, and authorities are established and communicated to foster accountability, performance assessment, and continuous improvement.

This directly maps to documented offshore/onshore OT roles, decision rights, escalation paths, and accountability.
NIST SP 800-53 Rev. 5

PM-1 — Information Security Program Plan

Program Management control family

Relevant requirement: The program plan includes identification and assignment of roles, responsibilities, management commitment, coordination among organizational entities, and compliance.

Use this as the formal evidence expectation for documenting responsibilities and coordination between operational, IT, supplier, and management entities.
NIST SP 800-82 Rev. 3

§3.3.1 — Establish OT Cybersecurity Governance

Section 3.3, Development and Deployment of an OT Cybersecurity Program

Relevant requirement: OT cybersecurity roles and responsibilities should be coordinated and aligned with internal roles and external partners.

This is the OT-specific basis for including operations, vendors, supply chain, engineering, and other non-IT personnel in the responsibility model.

Assessment focus