Skip to content

Compliance

ISO 27001 in OT Environments: Extending the ISMS Beyond the IT Perimeter

Many industrial organizations already hold ISO 27001 for IT. Extending it to OT environments demands a specific approach: different threat models, operational constraints and integration with IEC 62443.

3 min read

Why ISO 27001 Alone Is Not Enough in OT

ISO 27001 is the reference standard for information security management systems. It is the most widely adopted cybersecurity standard in the world, and it is present in almost every large industrial organization, at least for the IT side.

The problem is that ISO 27001 was designed with IT in mind. Its controls, its terminology, its risk framework: everything reflects a model where the priority is information confidentiality, where systems can be taken offline for maintenance, where patching is a normal and expected process.

In OT the priorities are reversed: operational availability first, then the integrity of process data, and finally confidentiality. An OT system does not shut down to install a patch. A security control that introduces latency may be unacceptable on a control network. An audit of a PLC in production requires coordination with process engineering, not just with the IT team.

Extending ISO 27001 to OT is possible and worthwhile, but it requires deliberate adjustments.

Defining the Scope: Where IT Ends and OT Begins

The first challenge in extending ISO 27001 to OT is scope definition. ISO 27001 requires an explicit definition of what falls within the management system: which sites, which processes, which assets.

For OT environments, the scope must be defined carefully. A few considerations:

IT/OT convergence: in many modern organizations, the boundary between IT and OT is fluid. MES systems communicate with the ERP; HMIs have network connections; production data flows to the cloud for analysis. Where IT ends and OT begins is not always obvious, and the answer directly affects the scope of the ISMS.

A gradual approach: it is often more practical to start with the certified IT scope and add OT components gradually, rather than trying to cover everything in a single project. A pilot production line or a specific site can be realistic starting points.

Documenting exclusions: if certain OT systems are explicitly excluded from the scope, the justification must be documented and defensible against the overall risk.

Annex A Controls Applied to the Industrial Domain

ISO 27001:2022 includes 93 controls in Annex A, organized into four themes (Organizational, People, Physical, Technological). Not all of them apply to OT in the same way.

Controls that apply directly: asset management (identifying and classifying all OT devices), access control (limiting access to control systems), backup (protecting PLC configurations), incident management (procedures for responding to incidents involving OT systems).

Controls that require adaptation: vulnerability management (OT patching cycles are far slower than IT ones, so the reasons and the compensating controls must be documented), change management (changes to OT systems require more extensive testing and validation), security monitoring (OT device logs have different formats and volumes from IT logs).

Controls to apply with caution: some standard IT controls are not directly transferable to OT without risking operational impact. Aggressive penetration tests on live control systems can cause outages. Complex password policies do not always apply to devices that do not support modern authentication interfaces.

ISO 27001 + IEC 62443: Complementary, Not Alternatives

A frequent question: if an organization wants to cover OT security, must it choose between ISO 27001 and IEC 62443?

The answer is that they are complementary, not alternatives.

ISO 27001 provides the management framework: the management system, the processes, the policies, the risk approach, the internal audits, the management review. It is organization oriented.

IEC 62443 provides the specific technical requirements for industrial control systems: the zones and conduits model, the Security Levels, the system and component requirements. It is technology and architecture oriented.

A mature industrial organization uses them together: ISO 27001 as the governance framework for the security program, IEC 62443 as the technical reference standard for OT requirements. IEC 62443 controls can be mapped onto ISO 27001 Annex A, creating an integrated system rather than two parallel silos.

Auditing and Maintaining Certification in OT Environments

Obtaining ISO 27001 certification for a scope that includes OT environments is possible, but the audits require specific competencies from the auditors.

The points auditors focus on in OT environments:

  • Asset inventory: the OT inventory is often less mature than the IT one. The lack of a complete inventory is a direct nonconformity.
  • Risk assessment: the risk assessment must include OT-specific scenarios, not just IT threats. Production disruption, safety compromise, physical damage to plants.
  • Compensating controls: for controls that cannot be implemented directly on OT systems (patches that do not apply, authentication that is not supported), the compensating controls adopted and their effectiveness must be documented.
  • Business continuity: business continuity plans must cover OT incident scenarios, with recovery procedures that account for the specific timelines and dependencies of industrial environments.

Certification is not the end goal: it is a measure of the program's maturity. An industrial organization that genuinely integrates OT into its ISO 27001 scope has taken a significant step toward truly coherent security management.

The MON5 Angle

Auditors examining an ISO 27001 scope extended to OT almost always start from the same point: the asset inventory. MON5 covers this evidence with the continuous asset inventory of the ANALYZE phase, fed by passive discovery that does not interfere with production, and documents vulnerabilities and compensating controls by correlating CVEs with EPSS scores and real exposure: the material the accepted-risk register needs.

The mapping onto IEC 62443 zones and conduits also supports the integration between the two standards described in this article. An OT assessment is the fastest way to reach the audit with solid evidence.

Related articles

Pharmaceutical production line with OT control systems and GMP validation

Compliance

Cybersecurity in Pharmaceutical Manufacturing: OT, GMP and Converging FDA Regulations

Pharma faces strict quality regulations that now overlap with OT cybersecurity needs. How to integrate GMP, FDA 21 CFR Part 11 and IEC 62443 into one coherent program.

3 min read
Cyber risk assessment for insurance policies in industrial OT environments

Risk Management

Cyber Insurance in Industry: Technical Requirements and How to Prepare for the Assessment

Insurers increasingly demand specific technical controls for OT environments. What they assess, how it affects the premium and how to prepare for the insurance assessment.

4 min read

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

Learn more about the regulation: ISO 27001

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna