Conduct Compliance and Assurance Activities for OT Cybersecurity
Overview
This standard defines the competencies required to conduct cybersecurity compliance and assurance activities in Operational Technology (OT) environments. It includes assessing OT systems against regulatory, industry, and organisational requirements; reviewing evidence; identifying non-conformities; and supporting improvements that maintain secure and resilient operations. It also incorporates assurance methods aligned with industry frameworks, including supplier assurance and governance reporting.
This standard is intended for OT cybersecurity professionals and assurance practitioners responsible for verifying OT security compliance.
Performance criteria
You must be able to:
- Identify OT cybersecurity regulations, standards, and organisational requirements that apply to industrial systems.
- Assess OT systems for compliance with regulatory, security, and organisational requirements.
- Conduct OT security assurance activities to verify controls and practices.
- Analyse evidence from audits and assessments to identify compliance gaps or risks.
- Review supplier and contractor compliance in line with organisational requirements.
- Document compliance findings and supporting evidence in line with organisational and regulatory processes.
- Communicate compliance outcomes to internal and external stakeholders.
- Monitor changes in regulatory and organisational requirements affecting OT systems.
- Support continuous improvement of OT compliance processes.
- Review assurance outcomes to support governance reporting and remediation planning.
Knowledge and Understanding
You need to know and understand:
- OT cybersecurity regulations and sector-specific requirements.
- Industry standards and frameworks applicable to OT systems.
- Methods for assessing OT compliance and verifying security controls.
- Evidence-gathering approaches suitable for OT environments.
- Supplier and contractor assurance requirements relevant to OT cybersecurity.
- Documentation practices for capturing compliance and assurance findings.
- Reporting requirements relevant to OT cybersecurity and governance.
- Concepts and approaches for continuous assurance in OT environments.
- Risk assessment principles relevant to compliance and assurance outcomes.
- Collaboration practices for working with engineering, safety, procurement, and governance teams.
- Organisational processes for managing remediation and non-conformities.
- How assurance outcomes support regulatory reporting and executive governance.
Scope/range
Scope Performance
Scope Knowledge
Values
Behaviours
Skills
Glossary
Assurance
Processes used to verify that systems meet required cybersecurity and operational expectations.
Compliance
Conformity with laws, regulations, standards, and organisational security requirements.
Non-Conformity
Any deficiency where a process, system, or control does not meet a defined requirement.
Audit Trail
A chronological record that provides evidence of control implementation, system changes, or user actions.
Remediation
Actions taken to correct identified gaps, non-conformities, or compliance weaknesses.