In critical infrastructure and industrial operations, the primary objective of security is preserving physical process integrity, physical safety, and operational uptime. Establishing effective defense across complex cyber-physical systems (CPS) requires concentrating resources on actionable, intelligence-driven safeguards. The SANS Institute established the Five ICS Cybersecurity Critical Controls to provide defenders with a prioritized baseline derived directly from the real-world tactics of operational adversaries.
What the SANS 5 ICS Cybersecurity Critical Controls are and why prioritizing them is necessary.
How the SANS controls map directly to overarching frameworks such as IEC 62443 and NIST (specifically NIST SP 800-82 and the NIST CSF).
Detailed breakdowns of each of the five critical controls: incident response, defensible architecture, visibility & monitoring, secure remote access, and risk-based vulnerability management.
How global regulatory shifts (CIRCIA, NIS2, SOCI) reinforce the necessity of operational security baselines.
Practical steps for implementing these controls systematically across people, process, and technology.
Established by the SANS Institute, the SANS Five ICS Cybersecurity Critical Controls represent an intelligence-driven baseline of essential security practices designed specifically to defend operational technology (OT) and cyber-physical systems (CPS). Derived directly from threat intelligence and adversary tactics targeting industrial infrastructure, these five controls prioritize the highest-impact defensive safeguards required to maintain physical safety, uptime, and process integrity.
Comprehensive industrial standards such as IEC 62443 or NIST SP 800-82 define the complete destination for operational security. However, attempting to implement hundreds of security controls simultaneously can stall progress. The SANS critical controls provide a prioritized starting point, ensuring defenders execute the five highest-leverage actions first to achieve immediate operational resilience.
The SANS five controls do not replace overarching standards; they operationalize them. The following crosswalk shows how each critical control aligns directly with global security frameworks:
SANS 5 Critical Control | IEC 62443 Alignment | NIST SP 800-82 / CSF Mapping |
1. ICS Incident Response | System Integrity & Incident Response (Part 2-4 / 3-3) | RS.RP (Response Planning) & Incident Handling |
2. Defensible Architecture | Zones & Conduits Architecture (Part 3-2) | PR.AC (Access Control) & Boundary Protection |
3. ICS Network Visibility & Monitoring | Continuous Monitoring & Asset Management (Part 2-1) | DE.CM (Continuous Monitoring) & ID.AM (Asset Management) |
4. Secure Remote Access | Wireless & Remote Access Controls (Part 3-3) | PR.AC (Remote Access Management) |
5. Risk-Based Vulnerability Management | Vulnerability & Patch Management (Part 2-3) | ID.RA (Risk Assessment) & PR.IP (Information Protection) |
Standard IT incident response plans focus on data containment and system isolation. In OT environments, abruptly isolating or shutting down a controller can trigger physical destruction, hazardous chemical releases, or severe power grid outages. ICS incident response must prioritize keeping the physical process operating in a safe posture through an active cyber event.
Organizations must establish scenario-based response plans derived from real-world threats (such as Triton/TRISIS or grid-targeted malware). Response strategies require cross-functional coordination between physical plant engineers and security operations to ensure containment steps never compromise plant safety.
Air gaps no longer exist in modern interconnected industrial facilities. A defensible architecture establishes logical boundaries, eliminates unmonitored connectivity, and creates choked inspection points between IT and OT, as well as between functional levels of the Purdue Model.
Industrial operators should enforce strict logical segmentation using firewalls and dedicated industrial DMZs. Network designs must support non-intrusive traffic collection via SPAN or TAP ports to maintain boundary visibility without disrupting time-sensitive control traffic.
You cannot defend what you cannot see. Traditional IT monitoring tools relying on active pinging or host agents fail in OT because they risk crashing sensitive industrial controllers. Real OT visibility requires passive deep packet inspection (DPI) of native industrial protocols to maintain a dynamic inventory of assets, firmware, backplane configurations, and baseline behavioral communications.
Defenders must deploy protocol-aware passive monitoring across operational segments. Moving beyond static asset spreadsheets to real-time asset discovery allows security teams to identify logic modifications, unauthorized commands, and emerging operational anomalies instantly.
Remote connections represent the single most targeted attack vector in OT environments. Unmanaged legacy VPNs, shadow connections, and third-party vendor pathways lack granular controls, exposing internal industrial networks to lateral movement.
Organizations must decommission legacy, always-on VPNs in favor of purpose-built, clientless OT remote access solutions. Enforcing multi-factor authentication (MFA), role-based just-in-time access, and full session video logging ensures third-party maintenance activities remain completely auditable and secure.
Because OT environments contain devices with decades-long lifecycles and strict uptime requirements, standard IT patching cycles are operationally impossible. Industry analysis indicates that only a small fraction (~4%) of key OT vulnerabilities are actively exploited in the wild. OT teams must prioritize vulnerabilities based on actual exposure, threat intelligence, and business criticality rather than raw CVE counts.
Security teams should correlate passive asset inventory data against threat intelligence feeds to identify weaponized exposures without active network scanning. Where software patching would cause unacceptable downtime, operators must deploy localized compensating controls, such as firewall port restrictions or network zone hardening, to mitigate risk effectively.
Implementing incident response, defensible architecture, secure access, or vulnerability management without asset visibility is impossible. OT network monitoring and automated asset inventory (Control No. 3) serve as the foundational prerequisite upon which the other four controls depend.
Achieving maturity across the SANS 5 controls requires aligning organizational pillars into a repeatable strategy:
Control Domain | People Pillar | Process Pillar | Technology Pillar |
Asset Visibility & Insights | Establish joint RACIs between Security and Plant Engineering. | Document asset lifecycle and business impact criticality. | Deploy non-intrusive passive discovery to map protocols and configurations. |
Exposure Management | Build a shared cyber-physical risk vocabulary. | Establish regular risk-acceptance review committees. | Correlate passive inventory with active threat intelligence & KEVs. |
Network Protection | Designate Network Security Liaisons for plant operations. | Design defensible zones (IEC 62443) & simulate access rules. | Enforce boundary firewalls, industrial DMZs, & microsegmentation. |
Threat Detection | Conduct joint tabletop exercises (TTX) with SOC and site operators. | Formulate alert triage SOPs aligned with MITRE ATT&CK for ICS. | Deploy behavioral alert engines to capture logic modifications. |
Secure Access | Align third-party vendors with strict security policies. | Enforce zero-trust, least-privilege remote maintenance SOPs. | Deploy clientless, MFA-enforced remote access with session recording. |
Operational security is increasingly tied to global compliance frameworks. In the U.S., pending requirements under CIRCIA will mandate rapid incident reporting for critical infrastructure, reinforcing the necessity of Control 1 (ICS Incident Response) and Control 3 (Visibility). Across the European Union, the NIS2 Directive and national enforcement laws such as Germany's NIS2UmsuCG demand strict access controls and supply-chain oversight—directly reflecting Control 4 (Secure Remote Access) and Control 2 (Defensible Architecture). Meanwhile, standards integrated under Australia's SOCI Act mirror the risk management expectations set by Control 5 (Vulnerability Management).
Aligning with the SANS 5 Critical Controls ensures that your organization not only achieves rapid risk reduction but also establishes the technical evidence and auditable logs required by global regulators.
Achieving continuous operational resilience requires unifying people, process, and technology into a cohesive CPS protection program. The SANS Five ICS Cybersecurity Critical Controls provide the tactical blueprint to move beyond reactive posture management into sustained, proactive defense across critical infrastructure.
To dive deeper into operationalizing these five controls across your facilities and achieving sustained operational resilience, download the full whitepaper: Aligning with the SANS 5 ICS Critical Controls to Achieve Continuous Operational Resilience.
What Is an OT Security Framework? Standards, Models, and How to Choose
How to Evaluate the CMMC Phase 2 Compliance Pause
Automate CPS Security Compliance Prep, No Spreadsheets Required
Interested in learning about Claroty's Cybersecurity Solutions?
Life, uninterrupted
We maximize your availability, strengthen your insurability, and support compliance to ensure operational resilience.