Authorities and standards board
Each record preserves the issuing authority, jurisdiction, instrument or authority type, legal or operating status, version and application dates, affected audience, workflow mapping, source link, and interpretation boundary.
NIST SP 800-82 Rev. 3
NIST describes OT topologies, threats, vulnerabilities, safeguards, and risk-management considerations while recognizing performance, reliability, and safety requirements.
NIST SP 800-82 Rev. 4 pre-draft
NIST initiated revision work to align the OT guide with current frameworks, standards, practices, and threat conditions and asked whether dynamic resources should replace several appendices.
NIST CSF 2.0
CSF 2.0 organizes cybersecurity outcomes across Govern, Identify, Protect, Detect, Respond, and Recover and can be applied alongside OT-specific guidance.
ISA/IEC 62443-2-1:2024
Part 2-1 defines security-program requirements for asset owners across governance, risk, implementation, maintenance, and continuous improvement of IACS security.
IEC PAS 62443-2-2:2025
The specification provides guidance for developing, validating, operating, and maintaining a set of technical, physical, and process security measures for IACS facilities.
ISA/IEC 62443-3-2
Part 3-2 addresses system-level risk assessment and the use of zones, conduits, and target security levels in IACS design.
ISA/IEC 62443-3-3
Part 3-3 defines system security requirements and security levels for industrial automation and control systems.
ISA/IEC 62443-4-1
Part 4-1 defines secure-development-lifecycle requirements for IACS product suppliers.
IEC 62443-4-2
Part 4-2 defines technical security requirements for IACS components using the foundational requirements and security-level framework.
CISA CPGs
CISA publishes a prioritized set of cybersecurity practices intended to reduce common and consequential risks across critical-infrastructure sectors.
Joint OT asset inventory guidance
The joint guide describes a regularly updated OT asset inventory and taxonomy tied to function and criticality as a foundation for risk, vulnerability, architecture, and incident-response work.
CISA Secure by Demand for OT
The guide presents security considerations and questions for OT buyers addressing product configuration, logging, identity, updates, vulnerability handling, support, and secure-by-design behavior.
CISA primary OT mitigations
The fact sheet calls attention to exposed OT connectivity and prioritizes defensive actions for owners and operators facing intentional targeting.
NERC CIP-015-1
CIP-015-1 requires documented processes for internal network security monitoring of specified high- and medium-impact BES cyber-system environments, including data feeds, anomaly detection, evaluation, and evidence.
TSA Pipeline-2021-02F
The directive continued performance-based requirements covering cyber risk assessment, plans, architecture, access, monitoring, incident response, testing, and related evidence for notified pipeline operators.
EU Cyber Resilience Act
The CRA establishes horizontal cybersecurity requirements for products with digital elements, including design, vulnerability handling, economic-operator, conformity, reporting, and market-surveillance provisions.
NIS2
NIS2 establishes cybersecurity risk-management, reporting, governance, supervision, and supply-chain requirements across essential and important entities.
C2M2 v2.1
C2M2 supports evaluation and improvement of cybersecurity capabilities across domains such as risk, assets, access, threat and vulnerability, situational awareness, response, continuity, third parties, workforce, architecture, and program management.
ATT&CK for ICS
ATT&CK for ICS organizes publicly reported adversary tactics, techniques, software, groups, mitigations, and data sources relevant to industrial control systems.
How to read the library
Binding requirements, official guidance, technical standards, implementation guides, program rules, and authority data are not interchangeable. Each page names the source class and states what it can and cannot establish about an organization or product.