CISA Industrial Control Systems (ICS) Security Guidance
CISA ICS: Seven Steps to Effectively Defend ICS

CISA Industrial Control Systems (ICS) Security Guidance CISA-ICS-7S-6: Implement Secure Remote Access

Remove obscure access vectors and back doors, especially modems; limit any remaining access. Where possible implement monitoring-only access enforced by data diodes (not software-enforced read-only); prohibit persistent vendor connections; require remote access to be operator-controlled, time-limited and procedurally similar to lock-out/tag-out; use the same paths for vendor and employee connections; and use two-factor authentication.

Other controls in CISA ICS: Seven Steps to Effectively Defend ICS

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.