The ICS Security and Management of Change: Risks and Resilience white paper, published by SANS Institute in March 2025, examines how management of change (MoC) processes reduce cybersecurity and operational risk in industrial control system (ICS) environments. Written by Jason Dely, the paper covers how unapproved, unexpected, and unmonitored changes to ICS cyber assets can affect physical operations, and outlines frameworks for classifying, tracking, and recovering from change.
Key findings:
- ICS changes fall into four categories: expected, unexpected, emergency, and unapproved, each with a different level of recoverability
- Unapproved changes are the hardest to recover from, described as extremely difficult without active monitoring, tracked changes, and accurate offline backups
- Three cyber elements are most affected by change: software (including firmware), code (programs, configurations, and parameters), and data
- Eight industry standards address change management for ICS security, including the ISA/IEC 62443 Series, NIST Special Publication 800-82, OSHA 1910.119, and API RP 1173
- Management of change activities map to four operational support areas: vulnerability management, monitoring, response, and improvement/recovery
- Building an accurate ICS asset inventory is a foundational challenge, complicated by isolated networks, transient devices like contractor laptops, and inconsistent methods for fingerprinting discovered assets
- Cybersecurity risks tied to unmonitored change span insider sabotage, ransomware extortion, attacker prepositioning for reconnaissance, and attack delivery
- Extreme caution, or avoidance altogether, is recommended when using online discovery tools not built by the original system vendor
- The volume of ICS changes peaks during Field Acceptance Testing (FAT) and Site Acceptance Testing (SAT), then drops sharply once a system enters operational service, typically stabilizing after one to two years
- Comprehensive change detection requires combining network-based monitoring with periodic comparison of online and offline files, since neither method alone provides full coverage
The paper's central argument is that ICS stability depends less on preventing change entirely and more on the ability to document, track, and revert it. Systems with strong recoverability practices can absorb both routine tweaks and emergency events with far less operational and security fallout than those relying on undocumented, ad hoc changes. This framing positions management of change as a practical bridge between operational reliability goals and cybersecurity outcomes, rather than a compliance exercise separate from day-to-day ICS operations.
This is an analytical white paper rather than a survey, written by SANS analyst Jason Dely and sponsored by Hexagon, drawing on ICS security standards and operational practice rather than primary survey data.