← Back to Project Support
About this sample: This document represents the output of the thinking. The value is in the conversations that produced it — the site walk, the stakeholder interviews, the engineering judgements made along the way. What you are reading is the record. The work that matters happened before the first page was written.
Project Parameters
Client
[REDACTED]
Project
[REDACTED]
Phase
FEED → Detailed Design
Duration
[REDACTED]
Lead Engineer
[REDACTED]
Standard
IEC 62443-2-4
Review Checkpoints
CheckpointPhaseReview FocusOutput
CP-01FEEDConcept architecture cybersecurity requirements. Initial zone/conduit model review.Advisory note + requirements register
CP-02Detailed DesignNetwork architecture diagrams, P&ID cyber risk review, vendor specification review.Design review report + RFI list
CP-03ProcurementVendor cybersecurity response evaluation. FAT criteria development.Vendor assessment report
CP-04CommissioningImplemented system verification against approved design. Deviation identification.Commissioning security sign-off
CP-05HandoverSecurity baseline documentation. Outstanding items closeout. Operational team briefing.Security baseline record
Note: Engagement scope and checkpoint structure are agreed at project initiation and adapted to your project timeline and governance framework.
Detailed Design Review

The following is an extract from the Checkpoint 02 design review. [N] findings were identified across network architecture, P&ID review, and vendor specifications.

Finding IDAreaObservationPriority
PS-F001Network ArchitectureNo industrial DMZ specified between IT and OT networks. Direct routing proposed between corporate LAN and control network — does not meet IEC 62443-3-2 ZCR requirements.High
PS-F004Remote AccessVendor remote access design proposes shared account. IEC 62443-2-4 SP.03.01 requires individual accountability. Design requires revision.High
PS-F007Vendor SpecificationCybersecurity requirements in vendor ITT do not specify minimum firmware version requirements or patch delivery obligations. Recommend amendment before ITT issue.Medium
PS-F011P&ID ReviewSafety instrumented system (SIS) network connectivity to OT LAN not documented in network diagrams. Potential uncontrolled communication path. Requires clarification.High
What this enables: For each checkpoint, NEXUS produces a formal review report, a findings register with recommended actions, and written advisory. All findings are tracked through to closure. Final handover includes a complete security baseline record for the operational team.