The ISA/IEC 62443-2-1 standard introduces Security Program Maturity Levels, which help assess how well an organization has integrated security into its industrial operations. Level 1 is the "Initial" stage where processes are ad-hoc, undocumented, and vary across the organization — precisely the case described in the question.
“Maturity Level 1 (Initial) — Processes are ad hoc and undocumented. There is no consistency in how security is implemented across the organization or teams. Security activities are performed inconsistently, typically in response to incidents.”
— ISA/IEC 62443-2-1:2010, Table 4 – Maturity Levels
The inconsistency between shifts and teams indicates a lack of standardized procedures, which is a hallmark of Level 1.
[References:, ISA/IEC 62443-2-1:2010 – Section 4.2.3, Table 4, ISA/IEC 62443-2-1 – Maturity Levels and Program Requirements, ===========, , , , ]
Submit