# SP-023 Industrial Control Systems

Status: published. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Security architecture for protecting industrial control systems (ICS), SCADA, and operational technology environments. Covers network segmentation between IT and OT, physical access to control equipment, secure remote maintenance, vulnerability management for legacy systems, and incident response for cyber-physical threats.
Use when: Any commercial or government organisation operating industrial automation equipment should implement this pattern. Typical applications include process control for production lines, energy generation and distribution (power plants, substations, smart grid), oil and gas (upstream, midstream, downstream), water and wastewater treatment, transportation infrastructure (rail signalling, traffic management, aviation),...
Not when: This pattern may be inappropriate where the automated process has genuinely low impact if it operates outside specified tolerance levels, there are very low availability requirements, and there is verified certainty that the system is isolated with strong logical and physical access controls.

## Controls (37, NIST SP 800-53 ids)
- Critical (7): AC-03, AC-17, CA-07, CM-02, CM-03, SC-07, SI-04
- Important (19): AC-06, AC-18, AU-02, CM-05, CM-07, CP-02, CP-09, CP-10, IA-02, IA-03, IR-04, IR-05, MA-04, PE-03, RA-03, RA-05, SI-02, SI-03, SI-07
- Standard (11): CA-02, IR-02, IR-07, MA-02, PE-04, PE-06, SC-08, SC-09, SC-23, SI-05, SI-10
- Withdrawn from SP 800-53 by NIST: SC-09 (now in SC-08)

## What each critical control mitigates (7)
- AC-03 Access Enforcement: T-IC-003
- AC-17 Remote Access: T-IC-003, T-IC-006
- CA-07 Continuous Monitoring: T-IC-002, T-IC-004, T-IC-009, T-IC-011
- CM-02 Baseline Configuration: T-IC-001, T-IC-007, T-IC-012
- CM-03 Configuration Change Control: T-IC-002
- SC-07 Boundary Protection: T-IC-001, T-IC-003, T-IC-004, T-IC-005, T-IC-009, T-IC-010, T-IC-012
- SI-04 System Monitoring: T-IC-004, T-IC-011

## Threats and the controls that mitigate them (12)
- T-IC-001 Targeted ICS Malware (Stuxnet, TRITON, Industroyer-class): SI-03, SI-07, CM-02, SC-07
- T-IC-002 Process Integrity Manipulation (Setpoint Tampering, Logic Bombs): CM-03, CM-05, CA-07, AU-02
- T-IC-003 IT-to-OT Lateral Movement: SC-07, AC-03, AC-17, IA-02
- T-IC-004 Industrial Protocol Exploitation (Modbus, DNP3 Command Injection): SC-07, SC-08, CA-07, SI-04
- T-IC-005 Ransomware Targeting OT Systems (EKANS/Snake, ICS-aware Variants): CP-09, CP-10, SI-03, SC-07
- T-IC-006 Unauthorised Remote Maintenance Access: AC-17, MA-04, IA-02, AC-06
- T-IC-007 Supply Chain Compromise (Firmware Tampering, Counterfeit Components): SI-02, SI-05, CM-02, PE-03
- T-IC-008 Physical Tampering at Remote Unmanned Facilities: PE-03, PE-04, PE-06, IA-03
- T-IC-009 Rogue Wireless Access Points in OT Environments: AC-18, PE-03, CA-07, SC-07
- T-IC-010 Exploitation of Unpatched Legacy ICS Components: RA-05, SI-02, CM-07, SC-07
- T-IC-011 Living-off-the-Land in OT Networks (Volt Typhoon-class APT): CA-07, AU-02, SI-04, AC-06
- T-IC-012 ICS-Specific Attack Toolkits (PIPEDREAM/INCONTROLLER, COSMICENERGY): SC-07, SI-03, SI-07, CM-02

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-023/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-023/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 32 KB: /api/v1/patterns/SP-023
- Page for people: /patterns/sp-023/
- Related: SP-017 Secure Network Zone Module; SP-025 Advanced Monitoring and Detection

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
