A Dedicated Program
Because of the uniqueness of OT and IoT technologies and the lack of full convergence, a dedicated program will be needed to ensure that these technologies are efficiently managed and secured as best as possible. With these technologies being significantly different from traditional IT, they need skill sets that are trained and specialized in managing them. This requires the need for a dedicated program to ensure they are gaining the attention they need, and that the correct controls are being implemented to reduce risk.
To keep consistency, it’s recommended to follow the same structure for the OT and IoT program as we have recommended for the broader cybersecurity program for IT.
This way, you can ensure the program is comprehensive and doesn’t contain any gaps.
Figure 12.8: OT and IoT program recommendation
As we have journeyed through the book, we have covered all the major functions represented above (GRC, which is Governance...