What are the most common ISO 27001 findings in manufacturing?

In manufacturing, ISO 27001 findings usually cluster around a few patterns: incomplete scoping, weak basic controls on the shop floor, and poor evidence that controls actually operate as designed. The specific findings vary by plant, auditor, and integration maturity, but the themes below come up repeatedly.

1. Incomplete or fuzzy scope for OT, MES, and test equipment

Many manufacturing organizations define an ISO 27001 scope focused on corporate IT while leaving operations technology (OT) and production data only partially covered.

  • Common findings:
    • Production lines, test stands, PLC networks, and lab systems not clearly included or excluded in the Statement of Applicability.
    • Ambiguity about whether MES, historians, and QMS are in-scope when they run in plants but are hosted centrally.
    • No clear mapping of information security requirements to product, process, and quality data in OT systems.
  • Why it happens: Brownfield environments with legacy equipment, mixed vendors, and long asset lifecycles make scoping politically and technically difficult.

2. Incomplete asset and information inventory

Accurate inventories are a core ISO 27001 expectation, but plants often have large blind spots.

  • Typical gaps:
    • No consolidated inventory of OT assets (PLCs, HMIs, industrial PCs, data loggers, machine controllers).
    • Test benches, programming laptops, and engineering workstations missing from the asset list.
    • Information assets such as NC programs, routings, recipes, test data, and calibration records not classified or even listed.
    • Shadow systems (access databases, local spreadsheets, scripts) used for production decisions with no registration.
  • Manufacturing nuance: Many assets are embedded in machines that cannot easily be scanned or taken offline for discovery, and OEM support contracts sometimes constrain configuration visibility.

3. Weak access control on shop floor and engineering systems

Access control findings are very common, especially where IT identity practices did not extend into OT.

  • Common findings:
    • Shared generic accounts on HMIs, industrial PCs, test stations, and maintenance laptops.
    • No individual authentication for changes to machine parameters, PLC logic, or NC programs.
    • Inconsistent revocation of access for contractors, temp workers, and transferred employees.
    • Uncontrolled local admin rights on engineering workstations and programming tools.
    • Remote access to vendors without strong authentication, time-bound access, or robust logging.
  • Typical root causes: Legacy devices that do not support modern authentication, cultural resistance on the shop floor, and incomplete integration between corporate identity systems and plant assets.

4. Insufficient change control for OT, MES, and automation

ISO 27001 expects controlled changes to information systems. In many plants, IT change management is formal, but OT and automation changes are handled informally.

  • Frequent findings:
    • No formal process for changes to PLC code, robot programs, test sequences, or recipes.
    • Inadequate versioning and rollback capability for automation and MES configuration.
    • Security impact not assessed when process changes are implemented (for example, adding networked sensors, remote diagnostic access, or new data exports).
    • Poor linkage between change records, validation/qualification records, and security risk assessments.
  • Brownfield challenge: Upgrading or revalidating production systems can be expensive and downtime-constrained, so plants often defer security-motivated changes until auditors highlight the risk.

5. Inadequate backup, recovery, and configuration management

Backups exist for central IT systems, but production environments often have partial or inconsistent coverage.

  • Common issues:
    • No tested backups of PLC programs, recipes, or machine parameter sets.
    • Backups stored only locally on the same network segment or in ad hoc engineer-managed archives.
    • Lack of documented, tested recovery procedures for MES, SCADA, or key plant databases.
    • Recovery objectives (RPO/RTO) not defined or not realistic relative to production impact.
  • Impact on findings: Auditors often flag the gap between documented policies (for example, enterprise backup standards) and the actual state of OT and plant-level systems.

6. Weak logging, monitoring, and incident handling in OT environments

ISO 27001 requires detection and management of security events. OT environments frequently lag behind IT in this area.

  • Typical findings:
    • Limited or no central logging from PLCs, industrial PCs, and OT network devices.
    • No clear incident response process that covers production systems and cross-functional roles (operations, maintenance, IT, quality, EHS).
    • OT events not integrated with SIEM or monitored only through OEM tools that plants rarely review.
    • No correlation between cyber incidents and quality/nonconformance investigations.
  • Dependency: Achieving robust monitoring in OT often depends on vendor support, network segmentation quality, and the tolerance for adding monitoring tools without requalification.

7. Removable media and data transfer controls

Removable media are still widely used in manufacturing for NC programs, firmware, and recipes, and are a common source of findings.

  • Common findings:
    • No consistent controls for USB sticks used to move programs into CNC machines, printers, or testers.
    • Personal or unvetted media used to load software or diagnostics tools onto industrial PCs.
    • Lack of scanning procedures or quarantine steps before media is connected to OT assets.
    • No logging or traceability of how critical programs and data are moved between systems.
  • Brownfield reality: For older machines without network connectivity, removable media may be the only practical option, so organizations must design controls that work despite this constraint rather than assuming full elimination.

8. Supplier, integrator, and OEM security oversight

Manufacturing relies heavily on OEMs, system integrators, and outsourced services for systems that affect information security.

  • Typical auditor observations:
    • Supplier security requirements not aligned with ISO 27001 controls, especially for MES, OT integrators, and equipment OEMs that provide remote access.
    • No formal review of third-party access to production networks (for example, VPN tunnels, remote monitoring boxes).
    • Unclear ownership of patching and hardening responsibilities for vendor-supplied systems.
    • Limited due diligence for cloud services used to process production, maintenance, or quality data.
  • Constraints: Changing OEM practices or renegotiating contracts can be slow and may trigger requalification of validated systems.

9. Policy, training, and awareness not adapted to plant realities

Policies often exist on paper but are written for office staff, not for operators, technicians, and engineers.

  • Common findings:
    • General information security policies that do not mention OT, MES, or production-specific scenarios.
    • Training that covers phishing but not practical issues like handling USB drives for CNC programs or vendor remote access.
    • Operators and maintenance staff unaware of their specific responsibilities under ISO 27001 controls.
    • No evidence that training effectiveness is evaluated in production settings.
  • Tradeoff: Tailored training takes time away from production and often competes with safety and quality training, so it must be prioritized deliberately.

10. Risk assessment and treatment not reflecting real plant risks

ISO 27001 is risk-driven. Many findings arise because the risk assessment does not match operational reality.

  • Typical gaps:
    • Risk assessments performed centrally without plant input, missing realistic threat scenarios (for example, impact of OT ransomware on batch traceability or calibration data).
    • Underestimation of dependencies on single critical systems such as legacy MES, historians, or license servers for engineering tools.
    • No linkage between information security risks and existing risk frameworks used for safety, process, or quality.
    • Treatment plans not aligned with validation constraints, downtime restrictions, or OEM limitations, making them hard to implement.

11. Documentation and evidence gaps

ISO 27001 places strong emphasis on documented information and evidence that controls operate. In manufacturing, this often exposes inconsistencies between what is written and what happens during production.

  • Recurring findings:
    • Procedures updated for ISO 27001 on paper but not rolled out or followed in plants.
    • Missing or incomplete records for periodic reviews, access recertifications, and log reviews.
    • Security considerations not integrated into existing document control, change control, and validation processes.
    • Legacy systems operating outside formal documentation, for example, old test stands kept in service.
  • Dependency: Closing these gaps often depends on aligning ISO 27001 documentation with existing QMS, MES, and engineering document control, rather than creating stand-alone security documents.

How brownfield constraints shape typical findings

Most manufacturing plants operate brownfield environments with mixed generations of equipment, various MES and SCADA platforms, and heavy validation burdens. This shapes findings in several ways:

  • Some controls (for example, strong authentication, centralized logging) are difficult to retrofit into old equipment without major redesign or requalification.
  • Downtime windows are short, so remediation plans must be phased, and auditors may cite findings about slow implementation, not just initial gaps.
  • Full replacement of legacy systems purely for security reasons is rarely realistic; auditors look instead for documented risk acceptance, compensating controls, and clear roadmaps.

Overall, the most common ISO 27001 findings in manufacturing are less about the absence of policies and more about inconsistent extension of those policies into OT, MES, and production data, constrained by long equipment lifecycles and integration debt.

Content classification

Visible verification fields for authorship, dates, taxonomy, and ST assignments.

Published:

Updated:

Tags:

FAQ category:

FAQ tag:

Glossary category:

Glossary tag:

Colour:

Content type:

Location:

Audience:

Intent:

Dev-only relationship debug

Content relationships

Rendered from saved content and bridge metadata. Nothing in this panel writes back to WordPress.

Inline glossary links

No inline glossary links found in saved content.

Attached glossary terms

No glossary bridge terms attached.

Attached FAQs

No FAQ bridge items attached.

Diagnostics

Inline glossary links
0
Attached glossary terms
0
Attached FAQs
0
  • No glossary or FAQ relationships found for this item.