OT Evidence Collection Checklist
Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.
Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.
Purpose
The artifacts worth retaining for each OT practice, grouped by the four evidence categories the site uses throughout: governance, configuration, operations, and validation.
How to use it
Fill in where each artifact actually lives and who maintains it. An evidence list with no location column is an aspiration; one with locations is a programme. Retain what you would want to show a reviewer who asks how you know a control operates.
The four evidence categories
| Category | What it answers |
|---|---|
| Governance | Who decided this, what did they decide, and who owns it now? |
| Configuration | What is actually configured, and does it match the decision? |
| Operations | Does it keep working during normal operations, and what happened when it did not? |
| Validation | How do you know — what did you test, when, and what was the result? |
OT evidence register
| Practice | Category | Artifact | Where yours lives / owner |
|---|---|---|---|
| OT-01 | Governance | OT access-control policy including vendor and break-glass procedures | |
| OT-01 | Configuration | Account inventory and privilege assignments per system | |
| OT-01 | Operations | Maintenance-window change records for credential changes | |
| OT-01 | Validation | Access-review sign-off and break-glass test results | |
| OT-02 | Governance | Inventory ownership and update policy | |
| OT-02 | Configuration | Inventory export with firmware and connectivity fields | |
| OT-02 | Operations | Walk-down worksheets with dates and signatures | |
| OT-02 | Validation | Reconciliation report: observed versus recorded assets | |
| OT-03 | Governance | OT segmentation architecture and zone/conduit policy | |
| OT-03 | Configuration | Boundary/DMZ and firewall rule exports enforcing default-deny | |
| OT-03 | Operations | Logs of cross-boundary traffic and investigated anomalies | |
| OT-03 | Validation | Segmentation test results showing blocked IT-to-OT access | |
| OT-04 | Governance | OT incident-response and recovery plan with roles and safe-state procedures | |
| OT-04 | Configuration | Inventory of controller logic/config backups used for recovery | |
| OT-04 | Operations | Exercise reports and incident after-action records | |
| OT-04 | Validation | Test-restore results and plan-revision history | |
| OT-05 | Governance | OT vulnerability/patch policy including compensating-control criteria | |
| OT-05 | Configuration | Vulnerability-to-asset mapping and applied compensating controls | |
| OT-05 | Operations | Maintenance-window patch records with test and rollback notes | |
| OT-05 | Validation | Decision log of patch-or-compensate with review dates | |
| OT-06 | Governance | Remote/vendor access policy with time-bound and emergency procedures | |
| OT-06 | Configuration | Jump-host/DMZ design and remote-access account settings | |
| OT-06 | Operations | Remote session logs and per-engagement provisioning records | |
| OT-06 | Validation | Test showing direct remote access is blocked; access-revocation records | |
| OT-07 | Governance | OT monitoring plan naming coverage, sensors, and alert ownership | |
| OT-07 | Configuration | Sensor placement and detection/alerting configuration | |
| OT-07 | Operations | Alert investigation records and baseline documentation | |
| OT-07 | Validation | Detection test result and sensor passivity confirmation | |
| OT-08 | Governance | OT resiliency/contingency plan with downtime targets and fallbacks | |
| OT-08 | Configuration | Controller backup inventory and redundancy/spares list | |
| OT-08 | Operations | Recovery-exercise reports and single-point-of-failure remediation | |
| OT-08 | Validation | Test-restore results measured against the downtime target | |
| OT-09 | Governance | Supplier inventory and OT supply-chain/security-terms policy | |
| OT-09 | Configuration | Firmware integrity-verification records and approved-source list | |
| OT-09 | Operations | Advisory monitoring and supplier risk assessments | |
| OT-09 | Validation | Evidence of pre-connection verification and agreement review | |
| OT-10 | Governance | OT change-management policy covering safety and security review | |
| OT-10 | Configuration | Change records with approvals, testing, and rollback notes | |
| OT-10 | Operations | Emergency-change log and post-change reviews | |
| OT-10 | Validation | Audit of recent changes against the process |
Limitations
Retaining these artifacts supports your own assurance and gives an assessor something concrete to review. It does not constitute an assessment, satisfy a contractual requirement, or establish a System Security Plan. What evidence is sufficient is a decision for your assessor and your contract, not for this checklist.
Nothing on this list should be actioned on a live operational-technology system without the process owner's agreement, an approved maintenance window, a tested rollback, and a safety review. Where a security action conflicts with safe operation, the safe operation wins and the control is compensated instead.
This is independent educational material. It supports planning and evidence collection; it does not establish compliance with NIST SP 800-171, DFARS 252.204-7012, CMMC, export-control obligations, or any contract requirement, and it is not an assessment. Tailor every item to your own technical, operational, contractual, regulatory, and safety requirements.
Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-ot-evidence-collection-checklist to keep filenames consistent across your team.