NIST SP 800-82 Rev 3
Evidence request list. 48 controls, 48 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Architecture
Segment OT networks into logical zones and conduits aligned with the Purdue model and IEC 62443, restricting traffic between zones via controlled conduits with documented data flows.
- Zone and conduit diagram
- Purdue level mapping
- Conduit data flow matrix
- Firewall policy aligned to zones
- Flat OT network
- Engineering workstations dual-homed to enterprise LAN
- No documented conduit list
Implement an Industrial DMZ between the enterprise (IT) and control (OT) networks to terminate and inspect traffic, prevent direct connections, and host shared services such as patch repositories and historians replicas.
- IDMZ architecture diagram
- List of services hosted in IDMZ
- Firewall rule sets terminating connections in IDMZ
- Reverse proxy or jump host configuration
- Direct IT to OT connections bypassing IDMZ
- Historian replicated directly to enterprise
- No reverse proxy for remote access
Apply multiple, layered, and complementary security controls across OT architecture so that failure of any single control does not compromise the system.
- Defense in depth control mapping
- Layer-by-layer control inventory
- Architecture review records
- Sole reliance on perimeter firewall
- No host-level controls on engineering workstations
- Missing application allowlisting
Isolate Safety Instrumented Systems (SIS) from the Basic Process Control System (BPCS) and other networks using physical or logical separation to preserve the integrity of safety functions.
- SIS network diagram
- Documented separation method
- Change records for SIS connections
- SIS cybersecurity assessment
- SIS sharing network with BPCS without separation
- Remote programming access to SIS
- No SIS cybersecurity assessment
Design OT wireless networks with strong authentication, encryption, segmentation from wired OT, interference mitigation, and continuous monitoring suitable for the operating environment.
- Wireless site survey
- WPA3 or equivalent configuration
- Wireless IDS records
- Spectrum monitoring evidence
- WPA2-PSK with shared key for years
- No rogue AP detection
- Wireless directly bridged into PLC VLAN
Host Security
Harden OT endpoints (HMIs, engineering workstations, servers) by disabling unnecessary services, removing default accounts, applying secure configuration baselines, and documenting deviations.
- Hardening baseline (CIS or vendor)
- Configuration scan results
- Deviation register
- Default Windows install on HMI
- Unnecessary services enabled
- No baseline scan
Use application allowlisting on stable OT endpoints to prevent execution of unauthorised software, particularly where signature-based anti-malware is constrained.
- Allowlist policy and product configuration
- Approved application list
- Block event logs
- Allowlisting in audit mode only
- No process to add approved applications
- Engineering workstations excluded
Deploy anti-malware solutions validated by the OT vendor where supported, configure scans to avoid impacting real-time operations, and maintain signature updates through approved paths.
- Vendor validation statements
- Scan scheduling configuration
- Signature update path documentation
- Anti-malware disabled to avoid CPU spikes
- Signature updates over six months old
- Real-time scanning during process upsets
Establish an OT patch management process that tests patches in a representative environment, schedules deployment during maintenance windows, and applies compensating controls when patching is not feasible.
- OT patch policy
- Patch test lab evidence
- Patch deployment records
- Compensating control register for unpatched systems
- No OT patch lab
- Patches applied without testing causing outages
- No compensating controls for unsupported OS
Control the use of removable media in OT environments through policy, scanning kiosks, port restrictions, and documented exception handling.
- Removable media policy
- Scanning kiosk logs
- USB port control configuration
- Exception register
- Unrestricted USB on engineering workstations
- No scanning kiosk
- Vendor USBs used without inspection
Manage changes to OT configurations, software, and firmware through documented approval, testing, version control, and rollback procedures.
- Change advisory board records
- Configuration baselines per device
- Version control for PLC logic
- Rollback procedures
- Undocumented PLC logic changes
- No version control for ladder logic
- Changes pushed without testing
Identity & Access
Establish account lifecycle controls for OT users, vendors, and service accounts including approval, provisioning, periodic review, and timely deprovisioning.
- Account request and approval records
- Quarterly account review evidence
- Leavers process records
- Departed contractors still active
- No service account inventory
- Shared local accounts on HMIs
Apply strong authentication mechanisms appropriate to the criticality of the OT function, manage credentials securely, and avoid default or shared credentials where operationally feasible.
- Authentication policy
- Default password change records
- MFA deployment scope
- Password vault inventory
- Default vendor passwords in use
- Shared HMI logins for operator shifts without compensating controls
- No MFA for engineering access
Grant OT users the minimum privileges needed and separate engineering, operator, and administrative roles to limit unauthorised configuration changes.
- Role definitions and permissions matrix
- RBAC configuration in HMI and historian
- Privileged access review
- All operators with engineering privileges
- No separation between admin and user accounts
- Privileged access not reviewed
Use physical controls such as key switches, locked cabinets, and tamper-evident seals when logical authentication on field devices is limited or absent.
- Cabinet lock inventory
- Key switch position policy
- Tamper seal logs
- PLCs left in RUN/REM allowing remote programming
- Cabinets unlocked
- No tamper detection
Provide remote access to OT only via authenticated, encrypted, and brokered pathways such as jump hosts with multi-factor authentication, session recording, and time-bounded access.
- Remote access policy
- Jump host configuration
- MFA enforcement records
- Session recording samples
- Time-bound access tickets
- Direct VPN into OT
- Shared accounts on jump host
- No session recording for vendors
Manage vendor remote access through individually identified accounts, contractual obligations, just-in-time enablement, supervision, and full logging.
- Vendor remote access agreements
- Just-in-time enablement procedure
- Supervision logs
- Vendor account inventory
- Always-on vendor tunnels
- Generic vendor service accounts
- No supervision during sessions
Incident Response
Develop and maintain an incident response plan that addresses OT-specific scenarios, integrates with safety and emergency procedures, and includes communications with regulators and vendors.
- OT IR plan
- Scenario playbooks
- Contact list including vendors and regulators
- IT plan reused with no OT scenarios
- No playbook for ransomware on engineering workstation
- No regulator notification timeline
Detect potential OT incidents through monitoring, operator reports, and safety alarms, and triage with criteria that account for cyber-physical impact.
- Triage criteria
- Operator reporting procedure
- Sample tickets with cyber-physical context
- Operators unaware of cyber reporting path
- Triage ignores process state
- No criteria for safety system involvement
Contain OT incidents using pre-authorised actions (network isolation, switching to manual control, safe state procedures) that balance security with safety and continuity of operations.
- Pre-authorised containment actions list
- Manual operating procedures
- Safe state procedures
- No pre-authorised isolation actions
- Operators not trained on manual operation
- Containment decisions delayed by approval chain
Capture forensic evidence from OT systems in a manner that preserves operational continuity, using non-disruptive techniques and chain-of-custody procedures.
- Forensics procedure for OT
- Approved tool list
- Chain-of-custody templates
- IT forensic tools used without OT validation
- No PLC memory capture process
- Evidence not preserved before reimaging
Conduct regular tabletop and functional exercises covering OT incident scenarios, involving operations, safety, security, and external stakeholders.
- Exercise schedule
- After-action reports
- Improvement actions tracker
- No exercises in 24+ months
- Operations not invited
- Lessons not implemented
Monitoring
Collect, retain, and review security-relevant events from OT devices, network gear, and supporting infrastructure, with retention aligned to incident detection and forensic needs.
- Log source inventory
- SIEM configuration
- Retention policy
- Sample correlation rules
- PLC logs not collected
- Retention under 30 days
- No correlation between IT and OT logs
Maintain an accurate, current inventory of OT assets including firmware versions, network locations, owners, and criticality, supported by passive discovery tooling.
- OT asset inventory export
- Passive discovery tool configuration
- Quarterly reconciliation evidence
- Spreadsheet-only inventory, last updated years ago
- Field devices missing
- No firmware version tracking
Use anomaly-based detection that learns normal OT traffic and process behaviour to identify unusual commands, new devices, or out-of-band changes.
- Baseline model documentation
- Anomaly tool deployment records
- Sample alerts and triage
- Tool deployed but not tuned
- No process variable monitoring
- Alerts ignored
Identify, assess, and remediate vulnerabilities in OT assets using passive tooling, vendor advisories, and risk-based prioritisation that accounts for safety and availability impact.
- Vulnerability scan results (passive)
- Vendor advisory subscription evidence
- Risk-based remediation tracker
- Active scanning crashing PLCs
- No vendor advisory subscription
- CVSS used without OT context
Network Security
Configure firewalls between OT zones with explicit deny-by-default policies, granular allowlists for required protocols, logging, and periodic rule review.
- Firewall rule export
- Quarterly rule review records
- Deny-by-default baseline
- Logging configuration
- Any-any rules between zones
- Unused rules accumulating
- No rule owner or expiry
Use deep packet inspection or protocol-aware filtering for industrial protocols (Modbus, DNP3, OPC, EtherNet/IP, PROFINET) to enforce allowed function codes and detect anomalies.
- DPI device configuration
- Allowed function code list per protocol
- Anomaly alerts log
- Stateless filtering only
- No function code restrictions on Modbus
- OPC traffic not inspected
Deploy passive network IDS tuned for OT protocols and baselined to normal operating traffic, with alerts routed to monitoring personnel familiar with the process.
- IDS sensor placement diagram
- OT signature/baseline configuration
- Tuning records
- Alert triage runbook
- IT IDS reused without OT signatures
- Sensors only at perimeter, none inside OT zones
- Alerts not routed to OT-aware analysts
Restrict and monitor outbound connections from OT to the internet and enterprise networks, denying direct outbound traffic from controllers and field devices.
- Egress firewall policy
- Proxy or jump host logs
- DNS allowlist for OT
- Cloud destination block list
- PLCs with direct internet egress
- No outbound proxy
- Permit-any outbound for engineering workstations
Provide authoritative, hardened time sources for OT devices to ensure consistent timestamps for event correlation, sequence of events recording, and forensic analysis.
- NTP server configuration
- Time source hierarchy diagram
- Drift monitoring records
- Each device pulling time from random internet NTP
- No internal stratum 1 source
- Unauthenticated NTP
Physical Security
Restrict physical access to OT areas, control rooms, network closets, and field cabinets using authenticated entry controls and visitor management.
- Access control system records
- Visitor logs
- Cabinet key inventory
- CCTV coverage map
- Shared badges
- Field cabinets accessible to any plant worker
- No CCTV on critical assets
Maintain environmental controls (temperature, humidity, power, fire suppression) appropriate to OT equipment and monitor for excursions.
- Environmental monitoring records
- UPS and generator test logs
- Fire suppression inspection records
- No environmental monitoring in remote substations
- UPS batteries expired
- No fire suppression in control rooms
Detect and respond to tampering of OT devices, cabinets, and network equipment through seals, sensors, alarms, and inspection procedures.
- Tamper seal logs
- Cabinet door alarm records
- Inspection schedule and findings
- No tamper seals
- Door alarms disabled
- No regular inspection
Recovery
Maintain offline, integrity-checked backups of OT configurations, PLC logic, HMI projects, and historian data, with tested restoration procedures.
- Backup inventory
- Offline copy storage records
- Restoration test logs
- Integrity verification
- Backups only on same network as systems
- No PLC logic backups
- Restoration never tested
Develop contingency plans for OT covering loss of view, loss of control, and degraded operations, including manual procedures and recovery time objectives.
- Contingency plan
- RTO/RPO definitions per system
- Manual operations procedures
- No defined RTO/RPO for OT
- Manual procedures missing or outdated
- Plan never exercised
Maintain spare PLCs, switches, servers, and media required for rapid replacement of failed or compromised OT components, with documented locations and integrity controls.
- Spare parts inventory
- Storage location records
- Periodic test of cold spares
- Critical spares unavailable
- Spares stored in same room as production
- No firmware version control on spares
Risk Management
Establish a documented OT security program with executive sponsorship, defined roles, and integration with the enterprise security program while recognising OT-specific safety and reliability constraints.
- OT security policy
- Charter signed by executive sponsor
- Roles and responsibilities matrix
- Annual program review minutes
- IT policy reused verbatim with no OT carve-outs
- No named OT security owner
- Safety stakeholders excluded from governance
Apply the NIST SP 800-37 Risk Management Framework to OT systems, tailoring categorisation, control selection, assessment, authorisation, and continuous monitoring to address safety, availability, and physical impact.
- System categorisation worksheets
- Control tailoring rationale
- Authorisation decisions (ATO)
- Continuous monitoring plan
- FIPS 199 impact levels copied from IT without OT impact analysis
- No ATO for legacy OT
- Continuous monitoring limited to IT tooling
Integrate cybersecurity risk management with functional safety processes so that security controls do not impair safety functions and safety hazards inform security requirements.
- Combined safety/security risk register
- HAZOP or LOPA outputs referenced by security plan
- Cyber-physical impact analysis
- Safety and security teams operate in silos
- Security changes deployed without safety review
- No cyber scenarios in HAZOP
Adopt a risk assessment methodology that considers likelihood, vulnerability, and consequence including safety, environmental, financial, and reputational impacts specific to OT.
- Risk methodology document
- Risk register
- Risk acceptance records
- IT-only risk scoring
- No consequence ranges for safety events
- Risk register not refreshed
Manage supply chain risks for OT including vendor security assessment, secure procurement language, software bill of materials, and ongoing monitoring of third parties.
- Vendor risk assessments
- Procurement security clauses
- SBOM repository
- Third-party monitoring records
- No security clauses in OT procurement
- SBOM not requested
- Vendors not reassessed after onboarding
Provide role-based security awareness and training for OT personnel, including operators, engineers, maintenance staff, and contractors, with content tailored to OT scenarios.
- Training curriculum
- Completion records
- Phishing exercise results
- Role-based modules
- Generic IT training only
- Operators not included
- No tracking of contractor completion
Protect sensitive OT documentation including network diagrams, system configurations, and incident details from unauthorised disclosure while ensuring availability to authorised personnel.
- Document classification scheme
- Access control on documentation repository
- Need-to-know reviews
- Network diagrams on open shares
- Vendor manuals public
- No classification applied
Operate a continuous monitoring program for OT controls that tracks effectiveness, identifies drift, and informs ongoing authorisation decisions.
- Continuous monitoring strategy
- Control effectiveness metrics
- Authorising official reports
- Annual point-in-time assessment only
- No metrics defined
- AO not briefed
Specific Sectors
Apply sector-specific overlays and regulations (electricity, water, oil and gas, manufacturing, building automation) on top of the 800-82 baseline, tailoring controls to operational realities.
- Sector regulation mapping
- Tailoring decisions
- Compliance evidence per sector framework
- No mapping to sector standard (NERC CIP, AWIA, TSA pipeline directives, etc.)
- Tailoring rationale missing
- Sector audit findings open
Apply OT security principles to building automation systems (HVAC, lighting, access control, elevators) that share many characteristics with industrial control systems.
- BAS asset inventory
- Segmentation from corporate IT
- Vendor remote access controls for BAS
- BAS on flat corporate network
- Default BACnet/Modbus exposed to internet
- No ownership for BAS security
Address security for geographically distributed OT (substations, pump stations, wellheads, remote terminal units) where physical access controls and connectivity options are constrained.
- Remote site security standard
- Communications security configuration (encrypted radio, cellular VPN)
- Site inspection records
- Unencrypted SCADA communications
- No physical inspection schedule
- RTUs with default credentials
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.