Cell Register
Regimes · SP 800-82

NIST SP 800-82 Rev 3

Attaches to every asset as the OT-specific overlay: architecture, remote access, patching in OT and incident response.

Who it binds: guidance addressed to the operator of the OT environment: it binds nobody in law and is what most OT security programmes are assessed against.

On the register, tick "NIST SP 800-82 Rev 3" and these rows appear on every asset the regime reaches. Source framework page on the compliance graph.

The rows, and when each attaches

Asset owner duty
on every asset
The OT overlay on every asset
SP 800-82 GOV-3 · HOST-4 · HOST-6 · IR-1 · MON-2
SP 800-82 is guidance for the operator of the OT environment: an inventory that holds firmware and location, safety and security run together, change and patch management, and an incident plan with OT scenarios.
Asset owner duty
where the asset is networked
Network architecture where the asset is on a network
SP 800-82 ARCH-1 · ARCH-2 · NET-1
Zones and conduits, an industrial DMZ between the plant and the office, and deny-by-default rules between zones.
Asset owner duty
where the asset is reached remotely
Remote access where the asset is reached remotely
SP 800-82 RA-1 · RA-2
A brokered, authenticated, recorded, time-bounded path; vendor accounts named individually and enabled just in time.
Asset owner duty
where the zone class is safety
Safety system isolation
SP 800-82 ARCH-4
The safety instrumented system is separated from the control system and every other network.
Asset owner duty
where the zone class is cell,line
Field devices in a cell or line zone
SP 800-82 IAM-4 · PHYS-1
Where a controller has little or no logical authentication, the key switch, the locked cabinet and the seal are the control.
Asset owner duty
where the family is utility
Building and utility plant
SP 800-82 SECTOR-2
Building and utility systems share the characteristics of the line and are the ones most often left on the corporate network.
On the register as a wholeSP 800-82 ARCH-1 · GOV-3 · MON-2 · REC-1

The OT overlay

SP 800-82 is guidance, not a legal duty, and it is what an OT security programme is assessed against. On the register it is the overlay on the IEC 62443 rows: zones and conduits and the industrial DMZ, remote access through a brokered and recorded path with vendor accounts enabled just in time, patching tested in a representative environment with compensating controls where it cannot be done, and an incident plan with OT scenarios. Safety instrumented systems are isolated from everything else.

The clauses, quoted

15 of 48 in the framework

Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

SP 800-82 MON-2 Asset Inventory and Visibility

Maintain an accurate, current inventory of OT assets including firmware versions, network locations, owners, and criticality, supported by passive discovery tooling.

Evidence an auditor accepts: OT asset inventory export; Passive discovery tool configuration; Quarterly reconciliation evidence
Common gap: Spreadsheet-only inventory, last updated years ago
Source framework: NIST SP 800-82 Rev 3
SP 800-82 GOV-3 Safety and Security Integration

Integrate cybersecurity risk management with functional safety processes so that security controls do not impair safety functions and safety hazards inform security requirements.

Evidence an auditor accepts: Combined safety/security risk register; HAZOP or LOPA outputs referenced by security plan; Cyber-physical impact analysis
Common gap: Safety and security teams operate in silos
Source framework: NIST SP 800-82 Rev 3
SP 800-82 HOST-6 Configuration Change Management

Manage changes to OT configurations, software, and firmware through documented approval, testing, version control, and rollback procedures.

Evidence an auditor accepts: Change advisory board records; Configuration baselines per device; Version control for PLC logic
Common gap: Undocumented PLC logic changes
Source framework: NIST SP 800-82 Rev 3
SP 800-82 HOST-4 Patch Management for OT

Establish an OT patch management process that tests patches in a representative environment, schedules deployment during maintenance windows, and applies compensating controls when patching is not feasible.

Evidence an auditor accepts: OT patch policy; Patch test lab evidence; Patch deployment records
Common gap: No OT patch lab
Source framework: NIST SP 800-82 Rev 3
SP 800-82 IR-1 OT Incident Response Plan

Develop and maintain an incident response plan that addresses OT-specific scenarios, integrates with safety and emergency procedures, and includes communications with regulators and vendors.

Evidence an auditor accepts: OT IR plan; Scenario playbooks; Contact list including vendors and regulators
Common gap: IT plan reused with no OT scenarios
Source framework: NIST SP 800-82 Rev 3
SP 800-82 ARCH-1 Network Segmentation by Zones and Conduits

Segment OT networks into logical zones and conduits aligned with the Purdue model and IEC 62443, restricting traffic between zones via controlled conduits with documented data flows.

Evidence an auditor accepts: Zone and conduit diagram; Purdue level mapping; Conduit data flow matrix
Common gap: Flat OT network
Source framework: NIST SP 800-82 Rev 3
SP 800-82 ARCH-2 Industrial Demilitarised Zone (IDMZ)

Implement an Industrial DMZ between the enterprise (IT) and control (OT) networks to terminate and inspect traffic, prevent direct connections, and host shared services such as patch repositories and historians replicas.

Evidence an auditor accepts: IDMZ architecture diagram; List of services hosted in IDMZ; Firewall rule sets terminating connections in IDMZ
Common gap: Direct IT to OT connections bypassing IDMZ
Source framework: NIST SP 800-82 Rev 3
SP 800-82 NET-1 OT Firewall Configuration

Configure firewalls between OT zones with explicit deny-by-default policies, granular allowlists for required protocols, logging, and periodic rule review.

Evidence an auditor accepts: Firewall rule export; Quarterly rule review records; Deny-by-default baseline
Common gap: Any-any rules between zones
Source framework: NIST SP 800-82 Rev 3
SP 800-82 RA-1 Secure Remote Access

Provide remote access to OT only via authenticated, encrypted, and brokered pathways such as jump hosts with multi-factor authentication, session recording, and time-bounded access.

Evidence an auditor accepts: Remote access policy; Jump host configuration; MFA enforcement records
Common gap: Direct VPN into OT
Source framework: NIST SP 800-82 Rev 3
SP 800-82 RA-2 Vendor Remote Access Controls

Manage vendor remote access through individually identified accounts, contractual obligations, just-in-time enablement, supervision, and full logging.

Evidence an auditor accepts: Vendor remote access agreements; Just-in-time enablement procedure; Supervision logs
Common gap: Always-on vendor tunnels
Source framework: NIST SP 800-82 Rev 3
SP 800-82 ARCH-4 Safety Instrumented System Isolation

Isolate Safety Instrumented Systems (SIS) from the Basic Process Control System (BPCS) and other networks using physical or logical separation to preserve the integrity of safety functions.

Evidence an auditor accepts: SIS network diagram; Documented separation method; Change records for SIS connections
Common gap: SIS sharing network with BPCS without separation
Source framework: NIST SP 800-82 Rev 3
SP 800-82 IAM-4 Physical Authentication for Field Devices

Use physical controls such as key switches, locked cabinets, and tamper-evident seals when logical authentication on field devices is limited or absent.

Evidence an auditor accepts: Cabinet lock inventory; Key switch position policy; Tamper seal logs
Common gap: PLCs left in RUN/REM allowing remote programming
Source framework: NIST SP 800-82 Rev 3
SP 800-82 PHYS-1 Physical Access Control to OT Assets

Restrict physical access to OT areas, control rooms, network closets, and field cabinets using authenticated entry controls and visitor management.

Evidence an auditor accepts: Access control system records; Visitor logs; Cabinet key inventory
Common gap: Shared badges
Source framework: NIST SP 800-82 Rev 3
SP 800-82 SECTOR-2 Building Automation System Security

Apply OT security principles to building automation systems (HVAC, lighting, access control, elevators) that share many characteristics with industrial control systems.

Evidence an auditor accepts: BAS asset inventory; Segmentation from corporate IT; Vendor remote access controls for BAS
Common gap: BAS on flat corporate network
Source framework: NIST SP 800-82 Rev 3
SP 800-82 REC-1 OT Backup and Restoration

Maintain offline, integrity-checked backups of OT configurations, PLC logic, HMI projects, and historian data, with tested restoration procedures.

Evidence an auditor accepts: Backup inventory; Offline copy storage records; Restoration test logs
Common gap: Backups only on same network as systems
Source framework: NIST SP 800-82 Rev 3

See what it attaches to your list

Paste the equipment list, tick the regime, and every asset it reaches carries these rows. Eight assets free, no account.

Build my cell register