Defining security audits
The security program plan needs to identify and document mandatory internal and external audits for regulatory compliance. In addition to compliance, the program plan document should clearly enumerate the frequency of internal audits to assess security operations in an IIoT deployment. The security assessment guidelines during a regular audit and when an audit is triggered by a security incident should also be documented.
The frequency and scope of security audits following device configuration changes, the authenticity of digital certificate and secrets stored in the device, tamper-proofing, and the device state following a firmware or software update should also be clearly enumerated and enforced.
The operational ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access