Insights · OT GRC · Part 2 of 2

How to build OT security documentation without stopping the plant

A practical, six-step approach that starts with what you already have and keeps the documents alive after the audit.

In our last post we covered why OT security documentation falls behind. Here is how we approach fixing it. The goal is simple: an accurate, usable set of documents, built without disrupting operations, that stays current after the project ends.

1. Start with what you already have

Before anyone walks the floor, collect what exists: as-built drawings, integrator handoff packages, firewall and switch configurations, PLC project files, vendor support agreements, existing policies, and past assessment reports. Much of what you need is already somewhere. The job is to pull it together and find where it no longer matches reality.

2. Build from data, not memory

Interviews matter, but people tend to remember the plant as it was designed. Configuration files and network data show the plant as it is. We use that data to build a digital model of the OT network, which becomes the foundation for the asset inventory and the architecture diagrams. Because the analysis runs on the model, nothing is scanned or changed on live equipment.

3. Verify on the floor

Then walk the systems with the people who run them. Confirm what the data shows, and capture what it misses: serial links, standalone systems, the vendor laptop in the cabinet. This is also where you learn how work actually gets done, which is what your procedures need to reflect.

4. Map once to the frameworks you answer to

Organize the documentation around the standards that apply to you:

  • NERC CIP for registered electric utilities
  • ISA/IEC 62443 for zones, conduits, and security levels across industrial sectors
  • NIST SP 800-82 for federal facilities and many public owners
  • CMMC where controlled unclassified information is in scope

One core set of documents can support several frameworks if you map it once instead of rewriting it for every audit.

5. Write policies operators can follow

OT policies and procedures have to reflect operational reality: maintenance windows, safety requirements, vendor support models, and systems that cannot be patched on an IT schedule. A short procedure people follow beats a long one that sits on a shelf. Where a control cannot be met, document the compensating measure and the reason. Auditors can work with an honest exception. They cannot work with silence.

6. Keep it alive

Documentation starts to decay the day the project ends unless it is tied to how work gets done. Link updates to your change management process, review the inventory and diagrams on a set schedule, and give every document a named owner. Collecting evidence continuously beats a scramble before every audit.

Where to start this quarter

If you do nothing else, get three things in place:

  • A current asset inventory for your critical systems
  • An honest network diagram that shows every remote access path
  • A one-page contact and recovery sheet for each critical system

Those three documents make every assessment faster, every incident easier to handle, and every next step clearer.

Questions about OT documentation or GRC? Reach out to Kelli Tarala, our Director of GRC, through our contact form.

Need a second set of eyes on your OT documentation?

Our GRC team builds OT documentation that holds up to audit and stays current after it.

Talk to our team

Get the FedShark brief

Occasional updates on protecting critical infrastructure, resilience, and OT workforce training for public organizations.