Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
CHECKLIST · OTv1.0 · REVIEWED 2026-07-28

OT Evidence Collection Checklist

Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.

Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.

Purpose

The artifacts worth retaining for each OT practice, grouped by the four evidence categories the site uses throughout: governance, configuration, operations, and validation.

How to use it

Fill in where each artifact actually lives and who maintains it. An evidence list with no location column is an aspiration; one with locations is a programme. Retain what you would want to show a reviewer who asks how you know a control operates.

The four evidence categories

CategoryWhat it answers
GovernanceWho decided this, what did they decide, and who owns it now?
ConfigurationWhat is actually configured, and does it match the decision?
OperationsDoes it keep working during normal operations, and what happened when it did not?
ValidationHow do you know — what did you test, when, and what was the result?

OT evidence register

PracticeCategoryArtifactWhere yours lives / owner
OT-01GovernanceOT access-control policy including vendor and break-glass procedures 
OT-01ConfigurationAccount inventory and privilege assignments per system 
OT-01OperationsMaintenance-window change records for credential changes 
OT-01ValidationAccess-review sign-off and break-glass test results 
OT-02GovernanceInventory ownership and update policy 
OT-02ConfigurationInventory export with firmware and connectivity fields 
OT-02OperationsWalk-down worksheets with dates and signatures 
OT-02ValidationReconciliation report: observed versus recorded assets 
OT-03GovernanceOT segmentation architecture and zone/conduit policy 
OT-03ConfigurationBoundary/DMZ and firewall rule exports enforcing default-deny 
OT-03OperationsLogs of cross-boundary traffic and investigated anomalies 
OT-03ValidationSegmentation test results showing blocked IT-to-OT access 
OT-04GovernanceOT incident-response and recovery plan with roles and safe-state procedures 
OT-04ConfigurationInventory of controller logic/config backups used for recovery 
OT-04OperationsExercise reports and incident after-action records 
OT-04ValidationTest-restore results and plan-revision history 
OT-05GovernanceOT vulnerability/patch policy including compensating-control criteria 
OT-05ConfigurationVulnerability-to-asset mapping and applied compensating controls 
OT-05OperationsMaintenance-window patch records with test and rollback notes 
OT-05ValidationDecision log of patch-or-compensate with review dates 
OT-06GovernanceRemote/vendor access policy with time-bound and emergency procedures 
OT-06ConfigurationJump-host/DMZ design and remote-access account settings 
OT-06OperationsRemote session logs and per-engagement provisioning records 
OT-06ValidationTest showing direct remote access is blocked; access-revocation records 
OT-07GovernanceOT monitoring plan naming coverage, sensors, and alert ownership 
OT-07ConfigurationSensor placement and detection/alerting configuration 
OT-07OperationsAlert investigation records and baseline documentation 
OT-07ValidationDetection test result and sensor passivity confirmation 
OT-08GovernanceOT resiliency/contingency plan with downtime targets and fallbacks 
OT-08ConfigurationController backup inventory and redundancy/spares list 
OT-08OperationsRecovery-exercise reports and single-point-of-failure remediation 
OT-08ValidationTest-restore results measured against the downtime target 
OT-09GovernanceSupplier inventory and OT supply-chain/security-terms policy 
OT-09ConfigurationFirmware integrity-verification records and approved-source list 
OT-09OperationsAdvisory monitoring and supplier risk assessments 
OT-09ValidationEvidence of pre-connection verification and agreement review 
OT-10GovernanceOT change-management policy covering safety and security review 
OT-10ConfigurationChange records with approvals, testing, and rollback notes 
OT-10OperationsEmergency-change log and post-change reviews 
OT-10ValidationAudit of recent changes against the process 

Limitations

Production and safety come first

Nothing on this list should be actioned on a live operational-technology system without the process owner's agreement, an approved maintenance window, a tested rollback, and a safety review. Where a security action conflicts with safe operation, the safe operation wins and the control is compensated instead.

OT Evidence Collection Checklist · version 1.0 · reviewed 2026-07-28 · file name batb-ot-evidence-collection-checklist

Generated from OT Top 10 at brilliantatthebasics.us. The live pages carry the current version of this guidance.

Independent educational material published by inDirectIT, Inc. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Cybersecurity practices must be tailored to each organization’s technical, operational, contractual, regulatory, and safety requirements.

All downloads

Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-ot-evidence-collection-checklist to keep filenames consistent across your team.