
NIST has issued its latest (fourth edition) of NIST SP 800-82 and has signalled it is moving away from a purely technical ICS/OT cyber security model and towards an enterprise risk and resilience model with a stronger mapping to CSF 2.0 and the six primary Functions.
The draft puts greater emphasis on:
Rather than treating OT security as a function owned by the engineering and/or cybersecurity teams, this latest draft connects OT risks to top level organisational objectives, business functions and broader enterprise risk management.
OT risk assessment needs to consider what happens if an asset or process is compromised, rather than simply whether the asset has a vulnerability.
For example, a vulnerable engineering workstation controlling a low-consequence process may warrant different treatment from an equally vulnerable system controlling a high-consequence chemical, energy or water process.
In OT, availability, integrity and safety can be more important than confidentiality, and taking a system offline to patch it may itself create operational or safety risk.
An updated risk approach should consider 'What is the consequence if this system is compromised or unavailable?' rather than simply 'How vulnerable is this system?'
Zero Trust has been the buzzword of the last decade or more and the principles and security architecture have become increasingly well embedded into many mature organisations.
In OT, network segmentation, trusted zones and implicit trust inside the OT network itself has been the standard. Especially in an environment where security controls must not interfere with safety and availability.
The latest guidance takes a stronger view on the application of ZTA and advises apply Zero Trust principles where they can be implemented without compromising OT safety and reliability.
It takes time to review changes to a substantial and important publication for high reliability industries.
A simple summary focuses on business processes, visibility, consequences and impacts, access and controls and detecting and recovering safely. A resulting OT security programme ultimately is condensed into six questions:
For those assessing their compliance against this new draft, performing a gap assessment and crosswalk against CSF 2.0 would be good initial actions during the review window.
CSF 2.0 adds Govern activities - including ownership, accountability, risk appetite, supply chain considerations and integration with enterprise risk management - and is the big addition in r4 that matters most. Moving on from a control centric view of OT to a world of managing the potential consequences should be the plan for 2027.
At 321 pages, it's a beast of a read for those looking to assess the draft and respond to the revisions before the deadline of 30 November 2026.
The document contains extensive information on OT cyber security, numerous architectures for sectors including rail and maritime operations, application of risk management practices and substantial appendices on threats, activities and how these relate to an OT overlay with tailored controls.
Those looking to submit feedback can do so via the comment template at SP 800-82 Rev. 4, Guide to Operational Technology (OT) Security.