OT DEFENSEREVIEW

Intelligence for systems that move the physical world.

Operating domain

Operating domain: Resilience, recovery, and cyber-informed engineering

The integration of cybersecurity with physical mission, safety, reliability, design, spares, configuration baselines, backups, manual capability, tested restoration, and recovery decision authority.

What this domain asks

The integration of cybersecurity with physical mission, safety, reliability, design, spares, configuration baselines, backups, manual capability, tested restoration, and recovery decision authority.

The domain should retain its own evidence, decision owner, materiality criteria, exception path, and consequence even when it shares organization identity, workflow, or technology with adjacent domains. Aggregation can support oversight; it should not erase the evidence behind different risks or operating outcomes.

Buyer questions

  • Which physical functions must continue, degrade safely, or recover within defined conditions?
  • Are logic, configuration, recipes, firmware, licenses, keys, vendor tools, documentation, and spares recoverable together?
  • Where can a security control create latency, loss of view, loss of control, nuisance trip, or common-mode dependence?
  • Who makes cyber, engineering, safety, process, and business decisions during an event?
  • When was recovery tested against representative assets and failure conditions without risking production?

Mapped workflows

Configuration, Baseline, And Change Monitoring

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for configuration, baseline, and change monitoring within this domain.

Incident Response And Recovery Support

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for incident response and recovery support within this domain.

Compliance Mapping And Control Evidence

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for compliance mapping and control evidence within this domain.

Cyber-Risk Quantification And Executive Reporting

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for cyber-risk quantification and executive reporting within this domain.

Offline And Air-Gapped Environment Support

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for offline and air-gapped environment support within this domain.

Device And Product Software-Supply-Chain Risk

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for device and product software-supply-chain risk within this domain.

Authority context

NIST SP 800-82 Rev. 3

NIST describes OT topologies, threats, vulnerabilities, safeguards, and risk-management considerations while recognizing performance, reliability, and safety requirements.

CISA CPGs

CISA publishes a prioritized set of cybersecurity practices intended to reduce common and consequential risks across critical-infrastructure sectors.

C2M2 v2.1

C2M2 supports evaluation and improvement of cybersecurity capabilities across domains such as risk, assets, access, threat and vulnerability, situational awareness, response, continuity, third parties, workforce, architecture, and program management.

Relevant operating models

Evidence boundary

OT Defense Review is not a regulator, standards body, certification body, control-system integrator, safety authority, engineering firm, incident-response provider, insurer, or law firm. Its records support market research and decision review; they do not establish compliance, certification, security, safety, reliability, exploitability, or fitness for a specific operational environment. A provider's documented capability can identify a research candidate but cannot establish buyer-specific adequacy for this domain.