NIST SP 1800-32
Evidence request list. 44 controls, 44 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Detect
Continuously monitor DER communications and operations to detect anomalies, unauthorized commands, or unexpected setpoint changes.
- monitoring tool configuration (OT-aware IDS or NSM)
- baseline behavior profiles
- alert rules for unauthorized commands
- setpoint change audit logs
- anomaly investigation reports
- no OT-aware monitoring deployed
- alerts not tuned to DER behavior
- setpoint changes not audited
Collect and centralize logs from DER devices, gateways, aggregators, and utility systems for security analysis and forensics.
- log collection architecture
- log source coverage matrix
- retention policy
- log integrity controls
- SIEM use case catalog for DER
- devices lack logging capability or capacity
- logs not centralized due to bandwidth
- retention shorter than incident detection cycle
Monitor the integrity of DER device settings, control logic, and configuration files to detect unauthorized changes.
- configuration baselines per device class
- hash or signature monitoring tool configuration
- change detection alert rules
- investigation procedure for unauthorized changes
- configurations not baselined
- no automated drift detection
- manual reviews instead of continuous monitoring
Governance
Establish governance structures for DER cybersecurity that span utility operations, IT, OT, regulatory affairs, and third-party aggregators.
- DER cybersecurity governance charter
- cross-functional committee minutes
- third-party oversight procedures
- executive reporting cadence documentation
- DER cybersecurity siloed within IT or OT only
- no formal committee
- third-party aggregators not held to documented requirements
Manage supply chain risk for DER components, including vendor risk assessments, contract requirements, and ongoing monitoring of vendor security postures.
- vendor risk assessment results
- contract clauses for DER vendors
- software bill of materials where available
- ongoing vendor monitoring records
- vendor incident notification procedures
- no SBOM for DER firmware
- vendor contracts lack security requirements
- no ongoing monitoring of vendor advisories
Identify
Maintain an inventory of Distributed Energy Resources (DER) assets, including solar inverters, battery systems, smart meters, gateways, and supporting communication equipment.
- DER asset inventory register
- site topology diagrams
- communication equipment inventory
- firmware version baselines
- vendor and model documentation
- customer-sited DER not inventoried by utility
- firmware versions not tracked centrally
- communication gateways missing from inventory
Map the data flows between DER assets, aggregators, distribution operators, and grid operators, including command and telemetry channels.
- DER data flow diagrams
- protocol inventory (IEEE 2030.5, DNP3, Modbus, OpenADR)
- interconnection point documentation
- third-party aggregator data sharing documentation
- protocols not documented at the message level
- aggregator-to-utility flows undocumented
- telemetry retention not specified
Conduct threat and risk assessments specific to DER deployments, considering grid stability impacts, safety impacts, and cyber-physical attack scenarios.
- DER threat model
- risk register with grid impact ratings
- attack tree analyses
- scenario library covering false data injection and unauthorized commands
- threat model treats DER as standard IT asset
- no grid impact severity scale
- cyber-physical scenarios omitted
NIST SP 1800-32: Access Management
Physical and logical access controls. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Access Management.
- Physical and logical access matrix for OT zones
- Electronic access perimeter device configurations
- Interactive remote access approval and session logs
- Personnel risk assessment outcomes for OT staff
- Shared engineering credentials remain in use
- Remote access lacks two-factor or session recording
- Vendor maintenance access without time-boxed approvals
- Personnel risk reassessment skipped during role changes
Personnel risk assessment. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Access Management.
- Physical and logical access matrix for OT zones
- Electronic access perimeter device configurations
- Interactive remote access approval and session logs
- Personnel risk assessment outcomes for OT staff
- Shared engineering credentials remain in use
- Remote access lacks two-factor or session recording
- Vendor maintenance access without time-boxed approvals
- Personnel risk reassessment skipped during role changes
Electronic access perimeter management. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Access Management.
- Physical and logical access matrix for OT zones
- Electronic access perimeter device configurations
- Interactive remote access approval and session logs
- Personnel risk assessment outcomes for OT staff
- Shared engineering credentials remain in use
- Remote access lacks two-factor or session recording
- Vendor maintenance access without time-boxed approvals
- Personnel risk reassessment skipped during role changes
Interactive remote access security. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Access Management.
- Physical and logical access matrix for OT zones
- Electronic access perimeter device configurations
- Interactive remote access approval and session logs
- Personnel risk assessment outcomes for OT staff
- Shared engineering credentials remain in use
- Remote access lacks two-factor or session recording
- Vendor maintenance access without time-boxed approvals
- Personnel risk reassessment skipped during role changes
Revocation of access procedures. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Access Management.
- Physical and logical access matrix for OT zones
- Electronic access perimeter device configurations
- Interactive remote access approval and session logs
- Personnel risk assessment outcomes for OT staff
- Shared engineering credentials remain in use
- Remote access lacks two-factor or session recording
- Vendor maintenance access without time-boxed approvals
- Personnel risk reassessment skipped during role changes
NIST SP 1800-32: Asset Identification & Governance
Critical asset identification and inventory. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Asset Identification & Governance.
- Operational technology asset inventory with criticality tags
- System security categorisation worksheet for OT assets
- OT security governance charter and steering minutes
- Roles and responsibilities for OT cyber-physical systems
- Inventory captures IT assets only, omits PLCs and RTUs
- Categorisation does not reflect safety impact ratings
- Governance forum lacks engineering or operations attendance
- OT-specific security policy missing or copied from IT
System security categorization. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Asset Identification & Governance.
- Operational technology asset inventory with criticality tags
- System security categorisation worksheet for OT assets
- OT security governance charter and steering minutes
- Roles and responsibilities for OT cyber-physical systems
- Inventory captures IT assets only, omits PLCs and RTUs
- Categorisation does not reflect safety impact ratings
- Governance forum lacks engineering or operations attendance
- OT-specific security policy missing or copied from IT
Security governance structure. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Asset Identification & Governance.
- Operational technology asset inventory with criticality tags
- System security categorisation worksheet for OT assets
- OT security governance charter and steering minutes
- Roles and responsibilities for OT cyber-physical systems
- Inventory captures IT assets only, omits PLCs and RTUs
- Categorisation does not reflect safety impact ratings
- Governance forum lacks engineering or operations attendance
- OT-specific security policy missing or copied from IT
Roles and responsibilities for critical systems. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Asset Identification & Governance.
- Operational technology asset inventory with criticality tags
- System security categorisation worksheet for OT assets
- OT security governance charter and steering minutes
- Roles and responsibilities for OT cyber-physical systems
- Inventory captures IT assets only, omits PLCs and RTUs
- Categorisation does not reflect safety impact ratings
- Governance forum lacks engineering or operations attendance
- OT-specific security policy missing or copied from IT
Security policy for operational technology. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Asset Identification & Governance.
- Operational technology asset inventory with criticality tags
- System security categorisation worksheet for OT assets
- OT security governance charter and steering minutes
- Roles and responsibilities for OT cyber-physical systems
- Inventory captures IT assets only, omits PLCs and RTUs
- Categorisation does not reflect safety impact ratings
- Governance forum lacks engineering or operations attendance
- OT-specific security policy missing or copied from IT
NIST SP 1800-32: Incident Response & Recovery
Incident response plan for operational disruptions. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Incident Response & Recovery.
- OT-specific incident response plan with safety triggers
- Recovery plan including manual operations fallback
- Reporting evidence to sector regulators
- Exercise records for blended IT/OT scenarios
- Response plan untested with engineering on-call rotation
- Recovery time objectives lack safety case validation
- Reporting channels to sector ISACs unconfirmed
- Exercises focus on IT scenarios without process impact
Recovery plan for critical systems. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Incident Response & Recovery.
- OT-specific incident response plan with safety triggers
- Recovery plan including manual operations fallback
- Reporting evidence to sector regulators
- Exercise records for blended IT/OT scenarios
- Response plan untested with engineering on-call rotation
- Recovery time objectives lack safety case validation
- Reporting channels to sector ISACs unconfirmed
- Exercises focus on IT scenarios without process impact
Reporting obligations to authorities. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Incident Response & Recovery.
- OT-specific incident response plan with safety triggers
- Recovery plan including manual operations fallback
- Reporting evidence to sector regulators
- Exercise records for blended IT/OT scenarios
- Response plan untested with engineering on-call rotation
- Recovery time objectives lack safety case validation
- Reporting channels to sector ISACs unconfirmed
- Exercises focus on IT scenarios without process impact
Coordination with sector-specific agencies. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Incident Response & Recovery.
- OT-specific incident response plan with safety triggers
- Recovery plan including manual operations fallback
- Reporting evidence to sector regulators
- Exercise records for blended IT/OT scenarios
- Response plan untested with engineering on-call rotation
- Recovery time objectives lack safety case validation
- Reporting channels to sector ISACs unconfirmed
- Exercises focus on IT scenarios without process impact
Exercises and drills for OT incidents. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Incident Response & Recovery.
- OT-specific incident response plan with safety triggers
- Recovery plan including manual operations fallback
- Reporting evidence to sector regulators
- Exercise records for blended IT/OT scenarios
- Response plan untested with engineering on-call rotation
- Recovery time objectives lack safety case validation
- Reporting channels to sector ISACs unconfirmed
- Exercises focus on IT scenarios without process impact
NIST SP 1800-32: Supply Chain & Configuration
Supply chain risk management for critical components. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Supply Chain & Configuration.
- Supply chain risk register for critical OT components
- Configuration management database for OT assets
- Change management approvals for OT modifications
- Vulnerability assessment reports with operational impact
- Component obsolescence not tracked against vendor roadmaps
- Configuration baselines not version controlled
- Emergency changes bypass risk assessment steps
- Vulnerability findings lack OT-aware compensating controls
Configuration management for OT systems. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Supply Chain & Configuration.
- Supply chain risk register for critical OT components
- Configuration management database for OT assets
- Change management approvals for OT modifications
- Vulnerability assessment reports with operational impact
- Component obsolescence not tracked against vendor roadmaps
- Configuration baselines not version controlled
- Emergency changes bypass risk assessment steps
- Vulnerability findings lack OT-aware compensating controls
Change management procedures. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Supply Chain & Configuration.
- Supply chain risk register for critical OT components
- Configuration management database for OT assets
- Change management approvals for OT modifications
- Vulnerability assessment reports with operational impact
- Component obsolescence not tracked against vendor roadmaps
- Configuration baselines not version controlled
- Emergency changes bypass risk assessment steps
- Vulnerability findings lack OT-aware compensating controls
Vulnerability assessment for critical systems. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Supply Chain & Configuration.
- Supply chain risk register for critical OT components
- Configuration management database for OT assets
- Change management approvals for OT modifications
- Vulnerability assessment reports with operational impact
- Component obsolescence not tracked against vendor roadmaps
- Configuration baselines not version controlled
- Emergency changes bypass risk assessment steps
- Vulnerability findings lack OT-aware compensating controls
NIST SP 1800-32: Systems Security
Security patch management for OT. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Systems Security.
- Patch management runbook with maintenance windows
- Network monitoring deployment with OT protocol awareness
- Hardening configuration baseline per device class
- Allow-list inventory for ports and services on OT assets
- Patches deferred indefinitely citing vendor support
- Monitoring lacks visibility into serial or proprietary buses
- Hardening baseline not validated after firmware updates
- Unused services remain enabled on legacy controllers
Malware prevention for operational systems. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Systems Security.
- Patch management runbook with maintenance windows
- Network monitoring deployment with OT protocol awareness
- Hardening configuration baseline per device class
- Allow-list inventory for ports and services on OT assets
- Patches deferred indefinitely citing vendor support
- Monitoring lacks visibility into serial or proprietary buses
- Hardening baseline not validated after firmware updates
- Unused services remain enabled on legacy controllers
Network security monitoring. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Systems Security.
- Patch management runbook with maintenance windows
- Network monitoring deployment with OT protocol awareness
- Hardening configuration baseline per device class
- Allow-list inventory for ports and services on OT assets
- Patches deferred indefinitely citing vendor support
- Monitoring lacks visibility into serial or proprietary buses
- Hardening baseline not validated after firmware updates
- Unused services remain enabled on legacy controllers
System security hardening. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Systems Security.
- Patch management runbook with maintenance windows
- Network monitoring deployment with OT protocol awareness
- Hardening configuration baseline per device class
- Allow-list inventory for ports and services on OT assets
- Patches deferred indefinitely citing vendor support
- Monitoring lacks visibility into serial or proprietary buses
- Hardening baseline not validated after firmware updates
- Unused services remain enabled on legacy controllers
Ports and services management. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Systems Security.
- Patch management runbook with maintenance windows
- Network monitoring deployment with OT protocol awareness
- Hardening configuration baseline per device class
- Allow-list inventory for ports and services on OT assets
- Patches deferred indefinitely citing vendor support
- Monitoring lacks visibility into serial or proprietary buses
- Hardening baseline not validated after firmware updates
- Unused services remain enabled on legacy controllers
Protect
Authenticate all communications between DER assets, aggregators, and utility systems using certificate-based or equivalent strong authentication mechanisms.
- certificate issuance procedures for DER assets
- PKI hierarchy diagram
- mutual TLS configuration on aggregator and utility endpoints
- certificate revocation procedure
- device enrollment records
- shared symmetric keys still in use
- no certificate revocation tested
- device enrollment relies on default credentials
Apply secure configuration baselines to DER devices, including disabling unused services, removing default credentials, and enabling secure protocols only.
- DER hardening baseline documents
- configuration audit reports
- default credential removal evidence
- service inventory per device class
- configuration drift detection results
- vendor default credentials remain on field devices
- hardening baseline not enforced post-deployment
- telnet or HTTP still enabled on legacy gateways
Segment DER operational networks from corporate IT networks and from public networks using firewalls, VLANs, and access control lists.
- network segmentation diagrams
- firewall rulesets between zones
- VLAN configuration
- data diode design where applicable
- zone-conduit model documentation
- flat network with DER on corporate VLAN
- firewall rules overly permissive
- no enforced separation between aggregator and utility zones
Apply cryptographic protections to DER communications including confidentiality and integrity of commands, settings, and telemetry.
- protocol-level encryption configuration (TLS, IPsec)
- integrity check mechanism documentation
- cipher suite policy
- key rotation procedures
- plaintext Modbus or DNP3 still in use
- TLS versions outdated
- no key rotation policy for embedded devices
Manage operator and administrator access to DER management systems with role-based access controls and multi-factor authentication.
- role catalog and permission mapping
- MFA enforcement evidence for operator consoles
- access review reports
- privileged access management logs
- joiner-mover-leaver records for DER operators
- shared operator accounts on SCADA HMIs
- MFA bypassed via local consoles
- access reviews missed for DER systems
Implement a secure firmware update process for DER devices that verifies authenticity and integrity of firmware images before installation.
- firmware signing key management procedure
- update verification procedure
- firmware update logs
- rollback capability documentation
- vendor signing chain validation
- firmware images not validated cryptographically
- no rollback procedure for failed updates
- vendor signing keys not pinned
Recover
Develop recovery plans for DER incidents that restore normal operations and verify integrity of devices and configurations before reconnection.
- DER recovery plan
- configuration restoration procedures
- device re-onboarding checklist
- integrity verification procedure post-recovery
- recovery time objective documentation
- recovery focused only on availability, not integrity
- no re-onboarding checklist
- RTO not defined for DER classes
Maintain backups of DER device configurations, control logic, and supporting system data to enable timely recovery.
- backup procedures and schedules
- configuration version control
- restoration test reports
- secure backup storage documentation
- device configurations not backed up
- restoration never tested
- backups stored on same network as production
Capture lessons learned from DER security incidents and feed them into program improvements, training, and updated procedures.
- post-incident review reports
- lessons learned register
- training updates based on incidents
- shared learnings with industry information sharing bodies
- lessons learned recorded but not implemented
- no sharing with E-ISAC or peer utilities
- training content not updated post-incident
Respond
Maintain incident response procedures specific to DER, including coordination with utility operations centers, aggregators, and emergency response authorities.
- DER-specific incident response plan
- coordination procedures with aggregators and operations centers
- tabletop exercise reports
- communication templates for grid operators
- regulatory notification procedure
- IR plan ignores OT and grid stability constraints
- no tested coordination with aggregators
- regulatory notification timing unclear
Define isolation and containment procedures for compromised DER assets that balance security response with grid stability and safety requirements.
- containment playbooks for compromised DER scenarios
- safe-state procedures for affected devices
- decision authority matrix during incidents
- post-incident analysis of containment actions
- isolation procedures may destabilize grid if executed blindly
- no documented decision authority for isolation calls
- safe-state procedures not tested
Communicate effectively with regulators, customers, aggregators, and vendors during DER security incidents.
- external communication plan
- regulator contact list
- customer notification templates
- vendor escalation contacts
- press and public communication policy
- no pre-approved templates for customer or regulator notification
- vendor escalation contacts outdated
- media response strategy missing
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 1800-32 framework page.