FM Global
Property Loss Prevention Data Sheets 7-110
October 2019
Interim Revision July 2024
Page 1 of 22
INDUSTRIAL CONTROL SYSTEMS
Table of Contents
Page
1.0 SCOPE ..................................................................................................................................................... 2
1.1 Hazard ............................................................................................................................................... 2
1.2 Changes ............................................................................................................................................ 2
2.0 LOSS PREVENTION RECOMMENDATIONS ........................................................................................ 3
2.1 Introduction ........................................................................................................................................ 3
2.2 Construction and Location ................................................................................................................. 3
2.3 Protection ........................................................................................................................................... 4
2.4 Human Factor .................................................................................................................................... 5
2.4.1 Management of Change Program ........................................................................................... 5
2.4.2 ICS Management .................................................................................................................... 5
2.4.3 ICS Security ............................................................................................................................. 6
2.5 Operation and Maintenance .............................................................................................................. 8
2.5.1 ICS Operations ........................................................................................................................ 8
2.6 Training ........................................................................................................................................... 10
2.7 Utilities ............................................................................................................................................. 10
3.0 SUPPORT FOR RECOMMENDATIONS ................................................................................................ 11
3.1 Fire Protection for Industrial Control Equipment ............................................................................. 11
3.2 ICS Management ............................................................................................................................. 11
3.2.1 ICS Oversight ....................................................................................................................... 11
3.2.2 Asset Management Program ................................................................................................. 11
3.2.3 Supply Chain Management Program .................................................................................... 11
3.3 ICS Security ..................................................................................................................................... 12
3.3.1 Access Management Program .............................................................................................. 12
3.3.2 Configuration Management Program .................................................................................... 12
3.3.3 Patch Management Program ................................................................................................ 12
3.3.4 Networking Safeguards ......................................................................................................... 12
3.4 Illustrative Losses ............................................................................................................................ 13
3.4.1 Ukraine Power Grid ............................................................................................................... 13
3.4.2 TRISIS ................................................................................................................................... 14
4.0 REFERENCES ....................................................................................................................................... 14
4.1 FM Global ........................................................................................................................................ 14
4.2 Other ................................................................................................................................................ 15
APPENDIX A GLOSSARY OF TERMS ....................................................................................................... 15
APPENDIX B DOCUMENT REVISION HISTORY ....................................................................................... 21
List of Figures
Fig. 3.3.4. Example communication path showing the Corporate/Internet DMZ and the ICS/Industrial
DMZ ............................................................................................................................................ 13
©2019-2024 Factory Mutual Insurance Company. All rights reserved. No part of this document may be reproduced,
stored in a retrieval system, or transmitted, in whole or in part, in any form or by any means, electronic, mechanical,
photocopying, recording, or otherwise, without written permission of Factory Mutual Insurance Company.