What this domain asks
The connected defensive workflow from approved telemetry and detection content through triage, process-context review, evidence preservation, incident decision, engineering coordination, containment, recovery, and learning.
The domain should retain its own evidence, decision owner, materiality criteria, exception path, and consequence even when it shares organization identity, workflow, or technology with adjacent domains. Aggregation can support oversight; it should not erase the evidence behind different risks or operating outcomes.
Buyer questions
- Which data sources and industrial protocols support each detection?
- What normal, abnormal, malicious, unsafe, and unknown states can the workflow distinguish?
- Can an analyst see process role and operating state before escalating?
- Who can authorize isolation, account action, process change, shutdown, or restoration?
- Can the team preserve raw evidence and reconstruct decisions after the incident?
Mapped workflows
Anomaly And Behavioral Detection
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for anomaly and behavioral detection within this domain.
OT Threat Intelligence And Detection Content
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for OT threat intelligence and detection content within this domain.
Alert Triage And Investigation Workflow
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for alert triage and investigation workflow within this domain.
Packet Capture And Forensic Evidence
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for packet capture and forensic evidence within this domain.
Incident Response And Recovery Support
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for incident response and recovery support within this domain.
Asset Criticality And Operational Context
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for asset criticality and operational context within this domain.
IT Security-Operations Integration And APIs
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for IT security-operations integration and APIs within this domain.
Offline And Air-Gapped Environment Support
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for offline and air-gapped environment support within this domain.
Authority context
NIST SP 800-82 Rev. 3
NIST describes OT topologies, threats, vulnerabilities, safeguards, and risk-management considerations while recognizing performance, reliability, and safety requirements.
NERC CIP-015-1
CIP-015-1 requires documented processes for internal network security monitoring of specified high- and medium-impact BES cyber-system environments, including data feeds, anomaly detection, evaluation, and evidence.
ATT&CK for ICS
ATT&CK for ICS organizes publicly reported adversary tactics, techniques, software, groups, mitigations, and data sources relevant to industrial control systems.
Relevant operating models
- OT Visibility And Threat-Detection Platform
- OT Managed Defense And Threat-Intelligence Platform
- Industrial OEM Security Portfolio
- Industrial Network Security And Segmentation Platform
Evidence boundary
OT Defense Review is not a regulator, standards body, certification body, control-system integrator, safety authority, engineering firm, incident-response provider, insurer, or law firm. Its records support market research and decision review; they do not establish compliance, certification, security, safety, reliability, exploitability, or fitness for a specific operational environment. A provider's documented capability can identify a research candidate but cannot establish buyer-specific adequacy for this domain.