CICSC provides a clear control structure for protecting critical systems, operational technology, and essential services.

Critical Infrastructure Cyber Security Controls (CICSC)

Containers as a Service

The Critical Infrastructure Cyber Security Controls (CICSC) provide a structured cybersecurity control framework for protecting Jordan’s critical infrastructure, including both information systems and operational technology (OT) environments.

The CICSC contains 405 customised cybersecurity controls organized into three implementation levels. The controls are derived from NIST SP 800-53 Rev. 5, NIST SP 800-82 Rev. 3, and NIST SP 800-53B, with additional considerations for critical infrastructure and OT environments.

Cryptika helps organizations assess their current cybersecurity posture against CICSC controls, identify implementation gaps, review supporting evidence, and develop practical remediation and implementation plans.




Gap Assessment

A gap assessment is a structured comparison between the organization’s current state and a defined target. The target may be an international standard, a regional regulation, a contractual requirement, a certification objective, a customer security requirement, an internal policy baseline, or a hybrid control framework


Gap Assessment

What the Framework Area Includes

CICSC covers 17 cybersecurity control families including access control, awareness and training, audit and accountability, security assessment and authorisation, configuration management, contingency planning, identification and authentication, incident response, maintenance, media protection, physical and environmental protection, planning, risk assessment, system and services acquisition, system and communications protection, system and information integrity, and supply chain risk management.

The controls are divided into three implementation levels:

  • Level 1: 135 controls providing baseline protection.
  • Level 2: 161 controls providing enhanced protection.
  • Level 3: 109 controls supporting protection against more advanced threats.

All organizations in scope are expected to implement Level 1 controls. Selection of Level 2 and Level 3 controls should be based on criticality and agreed between the critical infrastructure organization, relevant regulator, and Jordan’s National Cyber Security Centre.


Corporate Services


Cryptika can support CICSC alignment through current-state assessment, control-by-control gap assessment, implementation-level review, evidence assessment, IT and OT cybersecurity review, risk assessment, remediation planning, policy and procedure development support, control owner workshops, and management reporting.

The engagement can also cover technical areas directly addressed by CICSC, including access control, privileged access, authentication, logging and monitoring, configuration management, incident response, contingency planning, backup and recovery, vulnerability assessment, penetration testing, system communications protection, and supply chain cybersecurity.

Where required, CICSC controls can also be mapped against related cybersecurity frameworks to reduce duplication and support a consolidated compliance approach.


Click to check our applicable service

Compliance Implementation


Learn More

Risk
Assessment


Learn More

Advanced
Cyber Assessment


Learn More

Penetration
Testing

Learn More

Prerequisites

The client should prepare available cybersecurity policies and procedures, IT and OT asset inventories, system inventories, network and architecture diagrams, risk assessments, access-control evidence, privileged-account information, configuration standards, change-management records, security logs, vulnerability reports, penetration-testing reports, incident records, incident response plans, contingency and recovery plans, backup evidence, supplier information, security awareness records, and stakeholders for interviews.

The exact evidence requirements should be confirmed against the CICSC controls and implementation level included in the agreed scope.

Scope Caution

CICSC implementation must be scoped against the organization’s critical infrastructure environment, system criticality, applicable implementation level, regulatory expectations, and agreed control requirements.

Level 1 establishes the baseline controls, while the selection and adoption of Level 2 and Level 3 controls should be based on criticality and agreed between the critical infrastructure organization, relevant regulator, and Jordan’s National Cyber Security Centre.

Cryptika does not claim regulatory approval, authorization, or certification unless a separate official process applies and is formally confirmed.




Virtualization Solutions
Get in touch, our team will help you in planning your infrastructure
Get in Touch

FAQ

How many controls are included in CICSC?

CICSC contains 405 customised cybersecurity controls, consisting of 135 Level 1 controls, 161 Level 2 controls, and 109 Level 3 controls.

Does every organization need to implement all 405 controls?

No. Organizations are expected to implement Level 1 controls. Level 2 and Level 3 controls are selected based on criticality and agreement with the relevant regulator and Jordan’s National Cyber Security Centre.

Does CICSC cover Operational Technology?

Yes. CICSC specifically addresses information systems and Operational Technology (OT) and includes considerations explaining how controls may need to be applied within OT environments.

Can CICSC be mapped to the Jordan National Cybersecurity Framework?

Yes. The CICSC documentation states that the CICSC Annex provides relevant control alignment to the Jordan National Cybersecurity Framework.

Does CICSC include penetration testing?

Yes. CICSC includes CA-8 Penetration Testing, as well as independent penetration testing and red-team exercises within the Security Assessment and Authorisation control family.

Can Cryptika produce a remediation roadmap?

Yes. Identified CICSC gaps can be converted into prioritized remediation actions covering governance, technical controls, IT and OT environments, evidence requirements, responsible owners, and implementation priorities.