
ICS/SCADA (OT) Cybersecurity Self-Assessment Checklist: 154 Questions Mapped to NIST 800-82
OT doesn't fail like IT. A compromised control system can open a valve, override an alarm, or disable a pump, turning a network intrusion into physical damage. And the connections that make plants efficient, remote access, business-system links, internet exposure, are the ones that create the risk. This checklist shows an operator where they stand.
Every row is one question, grouped by NIST CSF function and mapped to NIST 800-82, with columns for corrective actions and a target date, so answering it builds a remediation list, not just a score. It's a baseline, not a full plant assessment.
Key Takeaways
- 154 questions organized by the five NIST CSF functions: Identify, Protect, Detect, Respond, and Recover.
- Built for critical infrastructure sectors: oil and gas, water and wastewater, chemical, manufacturing, and transportation.
- Covers the OT-specific concerns IT checklists miss: firmware update ownership, site-owner-managed firewalls and switches, physical security of control equipment, and safe-state recovery.
- Every question has space for corrective actions and a target completion date, so the filled sheet becomes a remediation tracker.
What's Inside
Every row is one question, grouped by NIST CSF function the way the framework groups them.
- Identify: asset management, business environment, governance, risk assessment, risk management strategy, supply chain.
- Protect: physical security, awareness and training, data security, information protection, maintenance, protective technology.
- Detect: anomalies and events, security continuous monitoring, detection processes.
- Respond: response planning, communications, analysis, mitigation, improvements.
- Recover: recovery planning, communications, improvements.
Columns for your comments or corrective actions and a target completion date on every row.
How to use it









