Solicitar documento

Para descargar este documento debe ser miembro con acceso a entregables. Si ya es miembro, puede descargarlo desde nuestra plataforma NGLibrary.

Document request

If you are interested in this document, you can ask for it at info@cci-es.org or register freely in our platform as a member able to access to deliveries.

ICMS Guide for those responsible for building an Industrial Cybersecurity Management System

978-84-947727-5-7

This guide makes it possible to cover the scarcity of normative references that deal, in a particular way, with the management of cybersecurity in industrial automation and control systems. In it, new specific and differentiated guidelines have been developed for an effective, efficient and continuous treatment of the risks to the availability, integrity and confidentiality of the operations and information managed by such systems.

In addition, if you want to learn and put into practice the implementation of an Industrial Cybersecurity Management System, we encourage you to sign up for the practical workshop that CCI organizes: T04. Workshop on the Application of an Industrial Cybersecurity Management System. It is based on this document (which will be delivered at no additional cost as workshop documentation), during which the following topics will be addressed:

  • Scope of application of the ICMS
  • Overview of the guide and its controls
  • Domain 1: Definition of a strategy.
  • Domain 2: Industrial Cybersecurity Risk Management
  • Domain 3: Promotion of a culture of Industrial Cybersecurity
  • Domain 4: Establishment of cyber protection regulations
  • Domain 5: Guarantee of Resilience and continuity

For further information, please visit: https://www.cci-es.org/AplicationICMS

If you prefer a more complete training in which to put this document into practice together with other publications of relevant interest, we encourage you to enroll in the practical course that CCI organizes: C02. Course of Cybersecurity Responsible in IACS (Industrial and Automation Control Systems).

Further information about this Course at: https://www.cci-es.org/CourseIACS

You can purchase this document on our NGLibrary
ES
20/09/2018
450€

Title

Study of High-Impact OT Incidents in the Railway Sector

15/04/2026

This document analyzes OT cybersecurity risks in the railway sector, considered an essential infrastructure. Through expert assessment, it models two key attacks: traffic management intrusion and “trackside” system manipulation. The report details the phases of these incidents, from initial access to systemic impact on operations. Finally, it proposes strategic solutions under the IEC 62443 standard […]

Industrial CRA Position Paper (Multisectoral)

24/11/2025

The new Industrial CRA Position Paper from the Industrial Cybersecurity Center highlights a critical need: adapting the European Cyber Resilience Regulation to the reality of OT environments. Critical infrastructures, legacy systems, decades-long life cycles, and the absolute priority of availability make it impossible to apply the CRA as currently designed. The document proposes a multisectoral […]

Pocket Guide – Questions to Ask Your Industrial Technology and Service Providers About Their Cybersecurity Capabilities

22/10/2025

This document, titled “Pocket Guide: Questions to Ask Your Industrial Technology and Service Providers About Their Cybersecurity Capabilities,” developed by the Industrial Cybersecurity Center (CCI), provides a structured set of questions designed to help organizations assess the level of maturity and commitment to cybersecurity among their industrial suppliers.