OT DEFENSEREVIEW

Intelligence for systems that move the physical world.

Operating domain

Operating domain: Asset inventory, context, and lifecycle

The maintained operating record for each OT asset's identity, role, location, owner, criticality, communications, dependencies, versions, configuration, support state, exposure, and recovery relevance.

What this domain asks

The maintained operating record for each OT asset's identity, role, location, owner, criticality, communications, dependencies, versions, configuration, support state, exposure, and recovery relevance.

The domain should retain its own evidence, decision owner, materiality criteria, exception path, and consequence even when it shares organization identity, workflow, or technology with adjacent domains. Aggregation can support oversight; it should not erase the evidence behind different risks or operating outcomes.

Buyer questions

  • What population and network boundary does each collection method see?
  • How are duplicate, transient, dormant, serial, virtual, and replacement assets resolved?
  • Which active methods are approved for each device class and operating state?
  • Can every field retain source, confidence, observation time, and responsible owner?
  • How does the inventory support maintenance, vulnerability, architecture, response, and recovery without becoming several conflicting records?

Mapped workflows

Passive OT Asset Discovery And Inventory

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for passive OT asset discovery and inventory within this domain.

Active OT-Safe Discovery And Query Governance

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for active OT-safe discovery and query governance within this domain.

Industrial Protocol Identification And Deep Packet Inspection

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for industrial protocol identification and deep packet inspection within this domain.

Topology, Communication, And Dependency Mapping

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for topology, communication, and dependency mapping within this domain.

Asset Criticality And Operational Context

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for asset criticality and operational context within this domain.

Firmware, SBOM, And Component Intelligence

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for firmware, SBOM, and component intelligence within this domain.

Configuration, Baseline, And Change Monitoring

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for configuration, baseline, and change monitoring within this domain.

Multi-Site Sensor, Data, And Policy Management

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for multi-site sensor, data, and policy management within this domain.

IT Security-Operations Integration And APIs

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for IT security-operations integration and APIs within this domain.

Authority context

NIST SP 800-82 Rev. 3

NIST describes OT topologies, threats, vulnerabilities, safeguards, and risk-management considerations while recognizing performance, reliability, and safety requirements.

NIST CSF 2.0

CSF 2.0 organizes cybersecurity outcomes across Govern, Identify, Protect, Detect, Respond, and Recover and can be applied alongside OT-specific guidance.

Joint OT asset inventory guidance

The joint guide describes a regularly updated OT asset inventory and taxonomy tied to function and criticality as a foundation for risk, vulnerability, architecture, and incident-response work.

Relevant operating models

Evidence boundary

OT Defense Review is not a regulator, standards body, certification body, control-system integrator, safety authority, engineering firm, incident-response provider, insurer, or law firm. Its records support market research and decision review; they do not establish compliance, certification, security, safety, reliability, exploitability, or fitness for a specific operational environment. A provider's documented capability can identify a research candidate but cannot establish buyer-specific adequacy for this domain.