Official intent
Secure the OT supply chain — know what your vendors and components bring into the plant. The official source remains authoritative.
Read the official campaign ↗Why it matters
OT compromises increasingly ride in through trusted suppliers — tampered firmware, vulnerable components, or an integrator's compromised laptop. You cannot audit everyone, but you can identify who matters most, hold them to security terms, and verify what enters the plant. This closes a channel that bypasses your perimeter entirely.
Minimum / Strong / Advanced
Critical suppliers, integrators, and components are identified, and security expectations are stated in agreements.
Equipment and firmware are verified before connection, vendor access follows the remote-access controls, and product advisories are monitored.
Supplier risk is assessed and tracked, provenance/integrity of firmware is checked, and supply-chain risk feeds procurement decisions.
Implementation timeline
- List critical suppliers, integrators, and single-source components
- Identify who can push firmware or updates into your OT
- Add security expectations to vendor agreements and onboarding
- Subscribe to advisories for the products you run
- Verify firmware/equipment integrity before connecting it
- Align integrator access with the remote-access controls
- Assess and record risk for the most critical suppliers
- Feed supply-chain risk into procurement decisions
Implementation steps
- Identify critical suppliers, integrators, and components — especially anyone who can update firmware.
- Set security expectations in agreements: patch support, vulnerability disclosure, and access rules.
- Verify equipment and firmware integrity and provenance before it is connected to the plant.
- Hold integrator and vendor access to the same brokered, logged remote-access controls.
- Monitor product advisories and assess supplier risk, feeding it back into procurement.
Validation
- Confirm critical vendor agreements include security and vulnerability-disclosure expectations.
- Verify a recent firmware or device was integrity-checked before connection.
- Check that advisories for your key OT products are being monitored and triaged.
Evidence to retain
Supplier inventory and OT supply-chain/security-terms policy
Firmware integrity-verification records and approved-source list
Advisory monitoring and supplier risk assessments
Evidence of pre-connection verification and agreement review
Common failure modes
Connecting new equipment without checking firmware, agreements that say nothing about security or patch support, and integrators granted broad standing access. Trusting a supplier is not the same as verifying what they deliver.
Framework mappings
Independent mappings are aids, not authoritative equivalence or compliance determinations.