
The Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency (CISA) have released a fact sheet, Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators, to help critical infrastructure organizations work with third-party industrial control systems integrators in establishing secure practices and frameworks for the operational environment.
Third-party ICS integrators provide various services that support CI organizations, such as design, installation, operational data analysis, device support and services, and daily operational control. CI owners and operators should apply the principle of least privilege within their operational environments to help ensure integrators can complete their assigned tasks while reducing the risk of threat actors exploiting third-party access.
Key recommendations include:
- Prepare contracts and service agreements that include cybersecurity and supply chain cybersecurity with requirements on key areas like data storage, remote access, patch policies, authorized personnel lists, and engineering controls to limit integrator lock-in.
- Evaluate devices with external internet exposure and work with integrators to understand and minimize exposure by disconnecting devices from public-facing internet (see CISA’s Internet Exposure Reduction Guidance).
- Ensure integrators access equipment through routes the organization is able to monitor.
- Request an inventory of all software and hardware supplied by the integrator, including documentation describing how it connects to infrastructure and how it will be updated.
- Practice procedures and maintain capabilities for manual operations, keeping in mind, and accounting for, where third parties fit into the environment and recovery procedures.






















