HomeDomainsCritical Infrastructure
Discipline 06

Critical Infrastructure

Resilience for CNI and OT environments — from NCA-ECC and OTCC to IEC 62443 and AESCSF — where a control failure is measured in outages, not records.

At a glance
  • SectorsEnergy, water, transport, health, telecoms, finance
  • AnchorsIEC 62443 · NCA OTCC · AESCSF / SOCI · NCA-ECC
  • ScoringMaturity engines with all-or-nothing and weakest-link rules
  • EvidenceNetwork posture from NSPM, rule by rule
Discipline 06
Why it matters

Critical Infrastructure

Critical infrastructure security is where information security meets engineering. Operational technology — the controllers, HMIs and safety systems that run a plant or a grid — was built to be available for decades, not patched every month, and the frameworks written for it reflect that: IEC 62443's zones and conduits, Saudi Arabia's OTCC for operators of industrial control systems, Australia's AESCSF for the energy sector and the SOCI obligations behind it.

These frameworks score differently from an ISO clause list, and the difference matters. AESCSF's maturity indicator levels are all-or-nothing: a single unmet practice holds the whole level back. SAMA's cyber framework reports the weakest applicable subdomain, not the average. A dashboard that averages these into a comfortable percentage misreports the regulator's own arithmetic.

GRCLens implements each framework's scoring rules as written — pinned by tests, so a catalogue update cannot quietly soften them — and keeps NSPM's network evidence beside the assessment, so segmentation is shown from the firewall rulebase rather than asserted from a diagram.

Discipline 06

What the platform does for CNI and OT

01

IEC 62443 as a catalogue framework

The asset-owner programme and the seven foundational requirements of IEC 62443-3-3, assessed control by control with evidence, on the same model as the rest of the library.

02

OTCC, in Arabic and English

NCA's Operational Technology Cybersecurity Controls with the official Arabic text of every control, domain and objective, and domain-by-domain assessment paging.

03

AESCSF maturity as the regulator scores it

MIL-1 to MIL-3 with the all-or-nothing rule enforced, SOCI risk-management-programme obligations mapped alongside, and the annual self-assessment exported.

04

Weakest-link reporting

Where a framework's own rule is the minimum, not the mean, the banner shows the minimum — and says which subdomain is holding it there.

05

Network posture as evidence

NSPM's rulebase analysis, segmentation findings and device compliance held as evidence beside the controls that require segmentation.

06

CIRMP under the SOCI Act

The Critical Infrastructure Risk Management Program document with its eleven prescribed sections, control statuses under the 2026 Enhanced Rules, a readiness check and Word/PDF export — kept apart from the AESCSF score, because they are different deliverables.

In the platform

How it shows up in a tenant

These frameworks are enabled per tenant like any other; these are the screens they add.

01

Maturity dashboards

OTCC, AESCSF, SAMA and Essential Eight with each framework's own scoring rule and its Arabic where the regulator publishes it.

02

IEC 62443 assessment

The asset-owner programme and the 62443-3-3 foundational requirements, with evidence per control.

03

NSPM

Devices, rules, objects, risk, topology and compliance for the network that carries the OT traffic.

04

CIRMP

The SOCI Act Part 2A programme document, drafted section by section with a readiness check before export.

Library

Frameworks in this discipline

ISA/IEC 62443

ISA/IEC 62443 Industrial Automation and Control Systems Security

ISA / IEC · International

Evidence industrial cybersecurity against ISA/IEC 62443 — from the security programme to the seven foundational requirements for control systems.

Open the framework page
AESCSF / SOCI

AESCSF & SOCI Act CIRMP Obligations (Australia)

AEMO (AESCSF) · Cyber and Infrastructure Security Centre (SOCI) · Australia

Evidence AESCSF maturity and SOCI Act risk-management obligations for Australian critical infrastructure — one assessment, board-ready reporting.

Open the framework page
NCA-ECC

NCA Essential Cybersecurity Controls

National Cybersecurity Authority (NCA) · Saudi Arabia

Assess, evidence and report against the Kingdom's Essential Cybersecurity Controls — in Arabic or English, hosted in your own environment.

Open the framework page
NSPM

Network Security Policy Management (NSPM)

GRCLens platform module · International

Govern firewalls and network policy operationally — device inventory, rule-base analysis, findings and compliance checks in one workspace.

Open the framework page
AU PSPF

Australian Protective Security Policy Framework (PSPF)

Australian Government — Department of Home Affairs · Australia

Assess protective security maturity across the PSPF domains — governance, risk, information, technology, personnel and physical security.

Open the framework page
NZ PSR

New Zealand Protective Security Requirements (PSR)

New Zealand Government (PSR — hosted by NZSIS) · New Zealand

Assess and evidence the Protective Security Requirements across GOVSEC, PERSEC, INFOSEC and PHYSEC — ready for annual PSR assurance reporting.

Open the framework page
Questions

Critical Infrastructure

Why does the AESCSF score drop to a lower level when one practice is unmet?

Because that is the framework's rule: a maturity indicator level is achieved only when every practice at that level is met. GRCLens applies the rule as published rather than averaging, and the demo data is shaped and tested to show it.

Is OTCC available in Arabic?

Yes. The OTCC catalogue carries NCA's official Arabic for every domain, subdomain, objective and control, alongside the English, and the assessment can be completed in either.

How is network segmentation evidenced?

Through NSPM, which analyses firewall rulebases and device configurations; its findings are held as evidence in the tenant beside the IEC 62443, OTCC and PCI DSS controls that require segmentation, so the evidence is the live rulebase rather than a network diagram.

Score OT the way the regulator does

A walkthrough of the OTCC and AESCSF assessments, the IEC 62443 zone model and NSPM's segmentation evidence, on a demo tenant shaped like your estate.