NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
OT Access Control and IAM
Implement OT access control per NIST SP 800-82 Rev 3 Chapter 6 (Security Architecture) + Chapter 7 (Applying the Cybersecurity Framework) covering identity + authentication + access management + remote access. Identity and access management must support (a) role-based access aligned to OT operational roles (operator + engineer + maintenance + vendor + reader-only + administrator), (b) multi-factor authentication for human users at every level above the field network (Level 2 and above) with hardware-token preferred for engineering and administrative roles, (c) emergency-bypass procedures documented and authorised that retain audit trail, (d) shared accounts only for legacy systems that genuinely cannot support individual identification + with compensating monitoring, (e) certificate-based machine-to-machine authentication where feasible, (f) directory federation between OT and IT only vi
- role-based access policy mapped to OT operational roles
- MFA configuration at Purdue Level 2 and above
- emergency bypass procedure with audit trail
- remote vendor access architecture + JIT approval workflow + session recording evidence
- credential management aligned with safety system requirements
- shared accounts pervasive without compensating monitoring
- vendor VPN persistent without PAM or session recording
- MFA absent on engineering workstations
OT Audit, Monitoring, Anomaly Detection
Implement OT audit + monitoring + anomaly detection per NIST SP 800-82 Rev 3 Chapter 6 (Security Architecture) + Chapter 7. OT audit and logging must (a) capture host audit events from OT workstations + engineering workstations + HMI + historian + AD + identity broker, (b) capture network telemetry via passive OT-aware sensors (Nozomi + Claroty + Dragos + similar) on key conduits, (c) capture device telemetry from PLCs + RTUs + safety instrumented systems where the device supports it, (d) retain logs aligned to regulatory + investigative + incident response requirements (often 90-365 days for OT). OT monitoring must (a) baseline normal OT behaviour (protocol distribution + asset communication patterns + setpoint range + sensor value range), (b) detect anomalies (new protocols + unauthorised devices + unexpected communications + setpoint excursion + sensor manipulation patterns), (c) inte
- OT audit log collection from hosts + network sensors + devices where supported
- OT behavioural baseline + anomaly detection rules + alerts triaged
- OT-aware SIEM rules + OT-specialised SOC capability or hybrid model
- OT threat intelligence consumption evidence
- OT monitoring limited to network perimeter (no host + device telemetry)
- IT SOC handles OT alerts without OT context producing miss + over-alert
- no OT-specific threat intelligence integration
OT Config, Patch, Vulnerability, Malware
Operate OT configuration + patch + vulnerability + malware protection per NIST SP 800-82 Rev 3 Chapter 6 + Chapter 7. Configuration Management must (a) establish baseline configurations per asset class + version + maintain canonical golden image library, (b) enforce change control with engineering + safety + cybersecurity review for OT changes, (c) detect drift via authenticated configuration scanning + integrity monitoring, (d) align with IEC 62443-2-3 patch management for OT. OT Patch Management must (a) test patches in pre-production OT lab matching production OT topology before deployment, (b) coordinate with vendor support cycles + extended-life OEM commitments, (c) schedule deployment during planned outage windows aligned with operations + safety + regulatory permits, (d) document compensating controls where patching is infeasible (legacy systems + vendor-restricted environments +
- baseline configurations + golden image library per asset class
- change control records with engineering + safety + cybersecurity review
- patch test lab evidence + production deployment record + compensating controls for unpatchable systems
- OT-aware vulnerability management with ICS-CERT + KEV + vendor advisory feed
- application allowlisting deployment + removable media transfer station + FIM evidence
- no patch test lab
- compensating controls undocumented for unpatchable systems
- traditional AV deployed without vendor support breaking OT
OT Incident Response and Recovery
Operate OT incident response + forensics + recovery + continuity per NIST SP 800-82 Rev 3 Chapter 6 + Chapter 7 + integration with NIST SP 800-61 Rev 2 IR methodology. OT IR must address (a) OT-specific incident response plan with OT scenarios (ransomware on OT + malware on engineering workstation + unauthorised PLC change + safety system tamper + vendor compromise + insider sabotage + supply chain compromise), (b) IR team including IT cybersecurity + OT engineering + plant operations + safety + legal + communications + executive leadership, (c) containment strategies adapted to OT (network isolation + asset cordoning + manual operation fallback) considering safety constraints first, (d) preservation of forensic evidence with OT-specific challenges (PLC volatile memory + transient protocol traffic + historian time-series + safety system event logs), (e) recovery procedures including know
- OT IR plan with OT scenarios + multi-disciplinary team + safety-first containment decision tree
- OT forensic procedures addressing PLC volatile memory + protocol traffic + historian + safety event logs
- recovery procedures + safety re-certification process where applicable + regulator notification process
- annual tabletop + biennial technical recovery + sector exercise participation
- IR plan IT-only without OT scenarios or team
- containment decisions without safety review
- no annual tabletop or technical recovery testing in OT
OT Network Architecture
Design and operate OT network architecture per NIST SP 800-82 Rev 3 Chapter 6 (OT Security Architecture). Apply the Purdue Enterprise Reference Architecture as the foundational structure: Level 0 Physical Process + Level 1 Basic Control + Level 2 Area Supervisory Control + Level 3 Site Operations + Level 3.5 DMZ + Level 4 Site Business + Level 5 Enterprise Business. Implement IEC 62443 zoned and conduit architecture: every zone has documented assets + trust level + security requirements + access policy + connected conduits with explicit traffic policy. Network segmentation must enforce (a) IT-OT separation with documented gateway + DMZ + protocol-aware firewall + unidirectional gateway (data diode) for highest-criticality boundaries, (b) intra-OT segmentation isolating safety instrumented systems + critical control loops from general OT, (c) remote vendor access via jump host + privilege
- authoritative network architecture diagrams using Purdue model + IEC 62443 zones/conduits
- asset inventory mapped to zones
- IT-OT segmentation evidence with gateway + DMZ + protocol-aware firewall + unidirectional gateway where applicable
- remote access architecture (jump host + PAM + session recording + JIT + MFA)
- air-gap assumption when real connectivity exists via vendor or maintenance
- flat OT network with no intra-OT segmentation
- remote vendor access via persistent VPN without jump host + PAM
OT Risk Assessment
Conduct OT risk assessment per NIST SP 800-82 Rev 3 Chapter 4 (Risk Management) + Chapter 5 (OT Risk Analysis) tailored to OT-specific risk model. Apply NIST SP 800-30 Rev 1 methodology adjusted for OT considerations (a) threat sources include nation-state targeting critical infrastructure + insider with engineering access + supply chain compromise of OT components + commodity malware with OT-impact, (b) vulnerabilities span OT protocols (Modbus + DNP3 + IEC 61850 + PROFINET + EtherNet/IP + OPC) + legacy systems with extended lifecycles + safety system reliance on availability + physical-cyber coupling, (c) impact dimensions include operational disruption + safety incident + environmental release + equipment damage + production loss + cascading regulatory + reputational + public health/safety harm, (d) likelihood considers exposure (internet + IT-OT interconnection + remote access + vend
- OT risk assessment per system / per zone with OT-adjusted methodology
- threat assessment integrating CISA + ICS-CERT + sector ISAC + nation-state intelligence
- vulnerability assessment covering OT protocols + legacy systems + safety dependencies
- OT risk register with Safety + Availability + Operational impact alongside CIA
- IT risk methodology applied unmodified
- no OT-specific threat intelligence consumption
- risk register lacks safety impact dimension
OT Security Program Governance
Establish an Operational Technology (OT) security program per NIST SP 800-82 Rev 3 Chapter 3 (OT Cybersecurity Program Development) and Chapter 4 (Risk Management). The program must (a) define OT scope distinct from IT (industrial control systems + SCADA + DCS + PLC + safety instrumented systems + building automation + transportation systems + medical devices where applicable), (b) document OT-specific risk tolerance recognising safety + reliability + availability priorities over confidentiality, (c) name accountable executives (CISO + Plant Manager + Safety Director + Operations Leadership) with documented decision authority, (d) integrate Safety and Security per Chapter 3 Section 3.7 covering shared assets + competing requirements + safety case integrity + cyber-physical interaction analysis, (e) align with NIST Cybersecurity Framework 2.0 OT profile + ISA/IEC 62443 + sectoral guidance
- OT cybersecurity program charter + named executive + roles + decision authority
- OT-specific policies (acceptable use + change control + access + remote + IR + BC + supply chain + safety isolation)
- safety-security integration decision authority + escalation path
- OT training program for engineers + operators + maintenance + contractors + vendors with completion records
- OT treated as appendix to IT cybersecurity program
- no documented safety-security trade-off authority
- training generic IT not OT-specific or not refreshed
OT Supply Chain, Lifecycle, Physical
Operate OT supply chain + asset lifecycle + physical security per NIST SP 800-82 Rev 3 Chapter 6 + Chapter 7. OT Supply Chain Security must (a) qualify OT vendors and suppliers per NIST SP 800-161 Supply Chain Risk Management tailored to OT (vendor cybersecurity maturity + product security incident response + vulnerability disclosure + secure development + provenance + SBOM availability + sub-component visibility), (b) embed cybersecurity requirements in procurement (RFPs + contracts + acceptance testing + warranty), (c) coordinate with vendor for product vulnerability handling + advisory consumption + patch availability + end-of-support planning, (d) document supply chain risks per asset and propagate through risk assessment. Secure System Lifecycle per Section 7 covering (a) Secure-by-design requirements for new OT systems, (b) commissioning security verification, (c) operational secur
- OT supply chain risk management per SP 800-161 OT-tailored + vendor qualification + SBOM + sub-component visibility
- procurement requirements with cybersecurity clauses + acceptance testing
- secure system lifecycle process + end-of-support compensating controls planning
- physical security architecture + visitor management + cabinet locks + environmental monitoring
- procurement does not include cybersecurity requirements
- end-of-support compensating controls planned reactively not proactively
- physical security limited to perimeter ignoring OT cabinets + control rooms
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security framework page.