2026 ASEE Annual Conference & Exposition

Compliance-Driven Containerized Security for ICS/SCADA Systems: Mapping Operational Metrics to NIST, ISO/IEC Frameworks

Presented at CIT Technical Session 12: Foundations and Emerging Topics.

As industrial control systems (ICS) and supervisory control and data acquisition (SCADA) environments increasingly adopt containerized and cloud-native technologies, the need for security frameworks that are both technically robust and regulatory-aligned becomes critical. This paper presents a compliance-driven approach to containerized security for ICS/SCADA systems, bridging operational metrics with established cybersecurity standards including NIST SP 800-82, ISO/IEC 27001, and the CISA Kubernetes Hardening Guide. Building upon prior work that introduced a Kubernetes-based testbed for simulating programmable logic controller (PLC) environments, this study extends the architecture to explicitly support compliance validation through measurable security indicators and structured policy enforcement.
The proposed framework maps key operational metrics, such as anomaly detection rates, role-based access control (RBAC) enforcement, and container isolation success to specific regulatory controls. These mappings are visualized through multi-tiered Sankey diagrams that trace the flow from technical enforcement to compliance outcomes. The testbed architecture comprises modular layers, including PLC simulators, telemetry filters, adversarial injection tools, and Kubernetes-native security primitives. Declarative YAML manifests define RBAC roles, network segmentation, and pod security standards, enabling reproducible enforcement and auditability.
Methodologically, the testbed simulates realistic ICS/SCADA conditions using containerized microservices orchestrated via Minikube. Legacy protocols such as Modbus and MQTT are emulated to preserve operational fidelity. Automation scripts in Bash and Go facilitate repeatable deployment, adversarial simulation, and data collection. Security controls are validated through scripted attacks, malformed API requests, and telemetry anomalies, with all events logged and correlated for forensic analysis.
Experimental results demonstrate high containment effectiveness: malicious pods were unable to traverse namespace boundaries, unauthorized API requests were consistently denied, and privilege escalation attempts were blocked by pod security constraints. Anomaly detection achieved a precision of 92.4% and recall of 88.7%, with low false positive rates. Compliance mapping confirmed full alignment with NIST SP 800-82 and CISA guidelines, and substantial alignment with ISO/IEC 27001, with minor gaps in procedural audit cycles.
To support broader adoption, the paper introduces two structured tables: one mapping implemented metrics to compliance standards, and another proposing additional metrics for future integration. These include data encryption status, backup integrity verification, and endpoint compliance scoring. Together, these metrics provide a roadmap for operationalizing compliance in ICS/SCADA environments.
By embedding compliance verification into the design and deployment phases, this framework transforms security from a reactive posture to a proactive, traceable, and standards-aligned discipline. The result is a scalable, reproducible platform for securing critical infrastructure that meets both technical and regulatory expectations. This work contributes a novel methodology for aligning containerized ICS security with formal compliance frameworks, offering practical tools for researchers, auditors, and infrastructure operators navigating the evolving landscape of industrial cybersecurity.

Authors
  1. Dr. Janne Hall Morgan State University [biography]
Download paper (857 KB)

Are you a researcher? Would you like to cite this paper? Visit the ASEE document repository at peer.asee.org for more tools and easy citations.