OT DEFENSEREVIEW

Intelligence for systems that move the physical world.

Authority library

Authorities and standards board

Each record preserves the issuing authority, jurisdiction, instrument or authority type, legal or operating status, version and application dates, affected audience, workflow mapping, source link, and interpretation boundary.

United States federal guidance with broad voluntary use · official federal technical guidance

NIST SP 800-82 Rev. 3

NIST describes OT topologies, threats, vulnerabilities, safeguards, and risk-management considerations while recognizing performance, reliability, and safety requirements.

United States federal publication process · pre-draft standards-development notice

NIST SP 800-82 Rev. 4 pre-draft

NIST initiated revision work to align the OT guide with current frameworks, standards, practices, and threat conditions and asked whether dynamic resources should replace several appendices.

Global voluntary use; organization-specific adoption · voluntary risk-management framework

NIST CSF 2.0

CSF 2.0 organizes cybersecurity outcomes across Govern, Identify, Protect, Detect, Respond, and Recover and can be applied alongside OT-specific guidance.

International voluntary standard; applicability depends on adoption, contract, certification, or authority · consensus industrial cybersecurity standard

ISA/IEC 62443-2-1:2024

Part 2-1 defines security-program requirements for asset owners across governance, risk, implementation, maintenance, and continuous improvement of IACS security.

International voluntary technical specification · publicly available specification

IEC PAS 62443-2-2:2025

The specification provides guidance for developing, validating, operating, and maintaining a set of technical, physical, and process security measures for IACS facilities.

International voluntary standard · consensus industrial cybersecurity standard

ISA/IEC 62443-3-2

Part 3-2 addresses system-level risk assessment and the use of zones, conduits, and target security levels in IACS design.

International voluntary standard · consensus industrial cybersecurity standard

ISA/IEC 62443-3-3

Part 3-3 defines system security requirements and security levels for industrial automation and control systems.

International voluntary standard · consensus industrial cybersecurity standard

ISA/IEC 62443-4-1

Part 4-1 defines secure-development-lifecycle requirements for IACS product suppliers.

International voluntary standard · consensus industrial cybersecurity standard

IEC 62443-4-2

Part 4-2 defines technical security requirements for IACS components using the foundational requirements and security-level framework.

United States critical-infrastructure guidance · official nonbinding cybersecurity guidance

CISA CPGs

CISA publishes a prioritized set of cybersecurity practices intended to reduce common and consequential risks across critical-infrastructure sectors.

Cross-national guidance for OT owners and operators · joint official technical guidance

Joint OT asset inventory guidance

The joint guide describes a regularly updated OT asset inventory and taxonomy tied to function and criticality as a foundation for risk, vulnerability, architecture, and incident-response work.

Cross-national guidance for OT digital-product buyers · joint official procurement guidance

CISA Secure by Demand for OT

The guide presents security considerations and questions for OT buyers addressing product configuration, logging, identity, updates, vulnerability handling, support, and secure-by-design behavior.

United States critical-infrastructure guidance · joint official defensive fact sheet

CISA primary OT mitigations

The fact sheet calls attention to exposed OT connectivity and prioritizes defensive actions for owners and operators facing intentional targeting.

Applicable registered entities and BES cyber systems within the approved scope · bulk-power-system reliability standard approved by FERC

NERC CIP-015-1

CIP-015-1 requires documented processes for internal network security monitoring of specified high- and medium-impact BES cyber-system environments, including data feeds, anomaly detection, evaluation, and evidence.

TSA-designated United States hazardous-liquid, natural-gas pipeline, and LNG owner/operators in stated scope · federal security directive

TSA Pipeline-2021-02F

The directive continued performance-based requirements covering cyber risk assessment, plans, architecture, access, monitoring, incident response, testing, and related evidence for notified pipeline operators.

European Union and products with digital elements within scope · binding EU regulation

EU Cyber Resilience Act

The CRA establishes horizontal cybersecurity requirements for products with digital elements, including design, vulnerability handling, economic-operator, conformity, reporting, and market-surveillance provisions.

EU Member State implementations and entities within scope · EU directive requiring national transposition

NIS2

NIS2 establishes cybersecurity risk-management, reporting, governance, supervision, and supply-chain requirements across essential and important entities.

Voluntary use across energy and other organizations · voluntary capability-maturity model

C2M2 v2.1

C2M2 supports evaluation and improvement of cybersecurity capabilities across domains such as risk, assets, access, threat and vulnerability, situational awareness, response, continuity, third parties, workforce, architecture, and program management.

Global defensive research resource · public knowledge base of adversary behavior

ATT&CK for ICS

ATT&CK for ICS organizes publicly reported adversary tactics, techniques, software, groups, mitigations, and data sources relevant to industrial control systems.

How to read the library

Binding requirements, official guidance, technical standards, implementation guides, program rules, and authority data are not interchangeable. Each page names the source class and states what it can and cannot establish about an organization or product.