Back to signals
CISA advisoryVulnerabilitiesPublished September 23, 2026

Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators

Introduction The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators. ICS is an umbrella term referring to integrated networks of hardware and software designed to monitor and automate physical processes, encompassing specialized control systems and devices, such as supervisory control and data acquisition (SCADA) systems and programmable logic controllers. Third-party integrators provide varying types of services for ICS, such as control system design, installation, operational data analysis, device support and service, and daily operational control. Critical infrastructure owners and operators should maintain caution when granting third-party ICS integrators high levels of access or control over industrial processes, ensuring the principle of least privilege (PoLP), is applied. PoLP within OT environments lends itself to granting users, processes, and systems only the minimu…

Open the source record
Tags
CISA
Related exam domains
CISSP 3: Security Architecture and Engineering; CISSP 4: Communication and Network Security; CISSP 5: Identity and Access Management; CISM 2: Information Security Risk Management; CISM 3: Information Security Program
Source record id
/node/25428
First seen by InfoSec Signals
9/23/2026

Exam domain labels come from a keyword heuristic and are study hints, not an official mapping. The summary is the publisher's own text, shortened; the linked record is authoritative.

Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators | InfoSec Signals