ISO/IEC 27001 is the international standard for an information security management system, or ISMS: a structured, risk-based way to manage security across an organization. It is widely adopted, certifiable, and increasingly expected by customers and regulators.

Most organizations build their ISMS around IT. Extending it to operational technology is both valuable and tricky, because OT changes the risk priorities and includes systems that do not fit neatly into IT-oriented controls. This article looks at how to map an ISMS to OT and where a dedicated OT standard is still needed.

01Key takeaways

  1. 01

    ISO/IEC 27001 defines a risk-based information security management system (ISMS), not a fixed checklist.

  2. 02

    Its strength is governance: scope, risk assessment, treatment and continual improvement.

  3. 03

    Applying it to OT means including OT assets and adjusting risk priorities toward availability and safety.

  4. 04

    Annex A controls apply to OT, but some need adaptation and OT needs controls 27001 does not detail.

  5. 05

    IEC 62443 complements 27001 by providing the OT-specific technical depth the ISMS can reference.

02What ISO/IEC 27001 is

ISO/IEC 27001 specifies the requirements for an information security management system: a framework of policies, processes and controls that an organization uses to manage security risk systematically. Certification against it demonstrates that this system exists and is operating.

Crucially, 27001 is not a prescriptive list of technical measures. It is a management system standard, focused on how an organization governs security: setting scope, assessing risk, selecting controls and improving over time. The specific controls are informed by Annex A and the related guidance in ISO/IEC 27002.

ISO 27001 is a way to manage security, not a recipe for it. The value is in the discipline of the system.

03The ISMS approach

At the heart of 27001 is a repeating cycle: define what you are protecting, assess the risks, decide how to treat them, implement controls, and review and improve. This management discipline is what makes security sustainable rather than a one-off project.

  • Define the scope of the ISMS, including which assets and systems it covers.
  • Assess risks to those assets in a consistent, documented way.
  • Treat risks by applying controls, accepting, transferring or avoiding them.
  • Operate the controls and maintain evidence that they work.
  • Review, audit and continually improve the system.

04Applying Annex A controls to OT

Annex A of ISO/IEC 27001 catalogs security controls spanning organizational, people, physical and technological themes. Many apply directly to OT: access control, asset management, supplier relationships, physical security, logging and more.

The work is in adaptation. An OT asset inventory must include controllers and devices, access control must account for vendors and engineering access, and physical security must cover plant environments. The control objectives hold, but their implementation has to reflect OT realities rather than assume IT systems.

05Adjusting risk priorities for OT

The biggest shift when extending an ISMS to OT is in the risk assessment itself. IT risk often centers on confidentiality; OT risk centers on availability and safety, where the consequence of compromise can be physical.

A risk assessment that treats an OT outage as merely a data-availability issue will misjudge it. The ISMS must weigh the operational and safety consequences appropriately, which often elevates controls that reduce reachability and protect the continuity of operations.

Controls that reduce exposure support several Annex A objectives at once. For OT assets that do not need continuous connectivity, an AIRGAPNET controlled connectivity approach can reduce reachability and produce the access and connection records an ISMS relies on as evidence.

06Where OT needs more than 27001

ISO/IEC 27001 provides the management system but not deep OT-specific technical detail. It tells you to manage risk and select appropriate controls; it does not tell you how to architect an industrial network.

This is where IEC 62443 fits. The ISMS can reference IEC 62443 for OT architecture, zones and conduits, and technical requirements, using 27001 for governance and 62443 for industrial depth. The two are complementary: one provides the system, the other the OT specifics.

07How it relates to NIS2 and DORA

A well-run ISMS is also a strong foundation for regulatory compliance. Regimes such as NIS2 and DORA expect risk management, incident handling and evidence, all of which an ISO/IEC 27001 ISMS is built to provide.

Rather than treating each requirement separately, organizations can use the ISMS as the backbone and map regulatory obligations onto it. The same risk assessments, controls and evidence serve certification and compliance together, including for OT once it is in scope.

08Closing thought

ISO/IEC 27001 gives an organization the management system to handle security deliberately rather than reactively. Extending it to OT is one of the best ways to bring industrial systems into the same disciplined risk management as the rest of the business.

Bring OT into scope, adjust the risk assessment for availability and safety, adapt the controls to industrial reality, and lean on IEC 62443 for the technical depth. The ISMS becomes a single, coherent way to govern security across both IT and OT.

FAQFrequently asked questions

What is ISO/IEC 27001?

ISO/IEC 27001 is the international standard for an information security management system (ISMS): a structured, risk-based framework of policies, processes and controls for managing security. It is certifiable and focuses on how an organization governs security rather than prescribing fixed technical measures.

Can ISO 27001 be applied to OT?

Yes. OT assets can be brought into the ISMS scope, with the risk assessment adjusted toward availability and safety and Annex A controls adapted to industrial realities such as controllers, vendor access and plant physical security.

How does ISO 27001 risk assessment change for OT?

IT risk often centers on confidentiality, while OT risk centers on availability and safety, where compromise can have physical consequences. The ISMS must weigh operational and safety impact appropriately, which often elevates controls that reduce reachability and protect continuity.

Is ISO 27001 enough for OT security on its own?

Not by itself. ISO 27001 provides the management system but not deep OT-specific technical detail. IEC 62443 complements it by supplying OT architecture, zones and conduits, and technical requirements that the ISMS can reference.

How does ISO 27001 relate to NIS2 and DORA?

A well-run ISMS provides the risk management, incident handling and evidence that regimes like NIS2 and DORA expect. Organizations can use the ISMS as a backbone and map regulatory obligations onto it, serving certification and compliance together.

SRCSources of record

One system, IT and OT

Bring OT into the same disciplined risk management.

Reduce exposure on OT assets that do not need continuous connectivity and capture the access records your ISMS relies on, supporting Annex A objectives and regulatory evidence at once.

Related article

Continue the thread IEC 62443 Zones and Conduits Explained: A Practical OT Segmentation Guide