ISO 27001 is based on the classic information security triad, often shortened to CIA:
- Confidentiality: Information is only accessible to people, systems, and processes that are explicitly authorized. In industrial environments this covers not just business data, but also product definitions, NC programs, process recipes, and configuration data in MES, historians, and controllers.
- Integrity: Information is complete, accurate, and protected against unauthorized or uncontrolled modification. For plants, this includes preventing unapproved changes to control logic, work instructions, quality records, and audit trails, and being able to detect and trace any changes that do occur.
- Availability: Information and systems are accessible and usable when required. In operations, this means keeping critical OT and supporting IT systems (e.g., MES, QMS, historians, engineering repositories) running at acceptable performance and with planned, controlled downtime.
How this plays out in regulated manufacturing environments
ISO 27001 does not prescribe specific technologies for OT or manufacturing IT. Applying confidentiality, integrity, and availability in a plant context typically involves:
- Layered controls across OT and IT: Network zoning, access control, monitoring, and backup strategies must work across brownfield equipment, legacy MES/ERP, and newer cloud or edge components. Many controls are constrained by vendor support limits and legacy protocol behavior.
- Traceability and change control: Protecting integrity and confidentiality usually means tight control over who can change system configurations, recipes, NC programs, and work instructions, and how those changes are requested, approved, implemented, and recorded.
- Managed availability, not maximum uptime at any cost: High availability has to be balanced with safety, validation, and change control. For example, applying patches or hardening controls may require planned downtime, requalification, or regression testing on validated systems.
- Coexistence with long-lifecycle assets: Many industrial systems cannot be simply replaced to meet ISO 27001 control expectations. Controls often need to be added around them (network isolation, jump hosts, procedural controls, monitoring) rather than through wholesale system upgrades.
In practice, using ISO 27001 in industrial operations is less about achieving a theoretical state of perfect confidentiality, integrity, and availability, and more about making documented, risk-based decisions on how far to go in each area, given real constraints on downtime, validation, and legacy infrastructure.