We baseren ons op IEC 62443, NIST SP 800-82 en NIS2. De audit dekt zes OT-domeinen die samen een
compleet beeld geven van security in uw industriële omgeving.
We draw on IEC 62443, NIST SP 800-82 and NIS2. The audit covers six OT domains that together provide
a complete picture of security across your industrial environment.
1. OT Governance & beleid
1. OT Governance & policy
Hoe is OT-security georganiseerd? We beoordelen beleid, rollen, risicomanagement en IEC 62443-compliance.
How is OT security governed? We review policies, roles, risk management and IEC 62443 compliance.
- OT-securitybeleid, rollen & verantwoordelijkheden.
- IEC 62443 zone & conduit model.
- Risico-analyse en NIS2-compliance.
- OT security policy, roles & responsibilities.
- IEC 62443 zone & conduit model.
- Risk assessment and NIS2 compliance.
2. Netwerksegmentatie & architectuur
2. Network segmentation & architecture
Hoe zijn IT- en OT-netwerken gescheiden? We beoordelen DMZ, firewalls, VLAN's en remote access.
How are IT and OT networks separated? We review DMZ, firewalls, VLANs and remote access controls.
- IT/OT-scheiding en DMZ-configuratie.
- Firewall-regels en netwerksegmentatie.
- Remote access, VPN en jump server configuratie.
- IT/OT separation and DMZ configuration.
- Firewall rules and network segmentation.
- Remote access, VPN and jump server configuration.
3. SCADA, PLC & HMI hardening
3. SCADA, PLC & HMI hardening
Hoe zijn SCADA-servers, PLC's en HMI's geconfigureerd? We beoordelen patchniveaus, wachtwoorden en firmwareversies.
How are SCADA servers, PLCs and HMIs configured? We review patch levels, passwords and firmware versions.
- Patchniveaus en firmwareversies.
- Standaard wachtwoorden en accounts.
- Onnodige diensten en open poorten.
- Patch levels and firmware versions.
- Default passwords and accounts.
- Unnecessary services and open ports.
4. Toegangsbeheer & identiteit
4. Access control & identity
Wie heeft toegang tot OT-systemen en hoe wordt dit beheerd? We beoordelen accounts, rechten en authenticatie.
Who has access to OT systems and how is it managed? We review accounts, privileges and authentication.
- Gebruikersaccounts en gedeelde accounts.
- Least privilege en role-based access.
- Multi-factor authenticatie voor remote access.
- User accounts and shared accounts.
- Least privilege and role-based access.
- Multi-factor authentication for remote access.
5. Monitoring, logging & incidentrespons
5. Monitoring, logging & incident response
Medewerkers, awareness en reactie op incidenten zijn cruciaal. We toetsen screening, training,
contracten en incidentprocessen.
People, awareness and response are critical. We review screening, training, contractual controls and
incident handling.
- Pre-employment checks, NDA’s en contractuele security-clausules.
- Security-training en awareness voor productie, IT en logistiek.
- Incidentidentificatie, melding, respons en herstel.
- Pre-employment checks, NDAs and contractual security clauses.
- Security training and awareness for production, IT and logistics staff.
- Incident identification, reporting, response and recovery.
6. Patchbeheer, back-up & continuïteit
6. Patch management, backup & continuity
Leveranciers werken zelf ook weer met cloud, 3rd tier partners en ontwikkelteams. We beoordelen hoe zij
daarmee omgaan en welke eisen zij doorvertalen.
Suppliers in turn rely on cloud, 3rd tier partners and engineering teams. We assess how they manage those
dependencies and propagate your security requirements.
- Contractuele eisen richting onderaannemers en cloudproviders.
- Secure design & development voor firmware, tools en portals.
- Toezicht op downstream-risico’s en kwetsbaarheidsbeheer.
- Contractual requirements for subcontractors and cloud providers.
- Secure design & development for firmware, tools and portals.
- Oversight of downstream risks and vulnerability management.