What a Watch signal means—and what it does not.
The public Watch is designed for discovery, prioritization, and source navigation. It deliberately stops short of facility applicability conclusions.
Source hierarchy
Primary sources are preferred: U.S. Coast Guard, CISA ICS advisories, CISA Known Exploited Vulnerabilities, vendor PSIRTs/CSAF, and FIRST EPSS for exploitation-probability context. CISA ICS acquisition uses CISA's official TLP:WHITE OT CSAF ROLIE feed from the cisagov/CSAF publication repository, while signal links remain on cisa.gov. Secondary reporting is not used as the authority for an applicability statement.
Inclusion criteria
Official CISA records classified as ICS Advisories are eligible for the Watch without a second keyword gate. KEV records are narrower: they enter only when a CVE is already present in selected CISA ICS intelligence, a strong industrial-control identifier is present, or a recognized OT vendor/product rule is satisfied. CVE-only entry is labeled as an ICS-linked relationship and records the related ICSA identifiers rather than implying that the generic KEV product independently passed the OT product selector. Matching is token-aware so ordinary IT strings such as driver, Virtual, Apache, or generic controller names cannot accidentally impersonate OT terms. Inclusion still does not assert that any port, terminal, vessel, or facility deploys that product.
Failure policy
Each live source has an independent checked timestamp and last-success timestamp. The curated registry is labeled separately as a local registry load rather than a live upstream verification. Successful CISA CSAF acquisition records the ROLIE feed timestamp and SHA-256 snapshot. CSAF normalization prefers explicit advisory/vulnerability summary notes over deployment-location metadata and qualifies generic series/model labels with the advisory product family when needed for reviewer clarity. If acquisition fails, prior live records for that source are preserved and the source is marked degraded. Successful-but-implausible empty or collapsed source responses are quarantined by plausibility gates instead of silently replacing known-good data.
KEV and EPSS
KEV is evidence of known exploitation for the listed CVE, not evidence that a particular asset is affected. EPSS is probability context, not impact or applicability. Both remain subordinate to exact product identity, version, configuration, and current vendor guidance.
Private applicability
TIDECAIRN Watchtower performs the facility-specific step locally. It is designed to preserve evidence provenance, surface evidence debt, and require human decisions where policy or criticality designation calls for them.