CISA Industrial Control Systems (ICS) Security Guidance
CISA ICS: Seven Steps to Effectively Defend ICS

CISA Industrial Control Systems (ICS) Security Guidance CISA-ICS-7S-5: Manage Authentication

Protect credentials, especially highly privileged accounts: implement multi-factor authentication where possible, reduce privileges to least necessary, enforce secure password policy (length over complexity), ensure unique credentials for all accounts including system/non-interactive, and rotate at least every 90 days. Require separate credentials and trust stores for corporate versus control-network zones and never share Active Directory or other trust stores between them.

Other controls in CISA ICS: Seven Steps to Effectively Defend ICS

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.