NIST SP 800-82 Rev 3
Attaches to every asset as the OT-specific overlay: architecture, remote access, patching in OT and incident response.
Who it binds: guidance addressed to the operator of the OT environment: it binds nobody in law and is what most OT security programmes are assessed against.
On the register, tick "NIST SP 800-82 Rev 3" and these rows appear on every asset the regime reaches. Source framework page on the compliance graph.
The rows, and when each attaches
| Asset owner duty on every asset | The OT overlay on every asset SP 800-82 GOV-3 · HOST-4 · HOST-6 · IR-1 · MON-2 SP 800-82 is guidance for the operator of the OT environment: an inventory that holds firmware and location, safety and security run together, change and patch management, and an incident plan with OT scenarios. |
|---|---|
| Asset owner duty where the asset is networked | Network architecture where the asset is on a network SP 800-82 ARCH-1 · ARCH-2 · NET-1 Zones and conduits, an industrial DMZ between the plant and the office, and deny-by-default rules between zones. |
| Asset owner duty where the asset is reached remotely | Remote access where the asset is reached remotely SP 800-82 RA-1 · RA-2 A brokered, authenticated, recorded, time-bounded path; vendor accounts named individually and enabled just in time. |
| Asset owner duty where the zone class is safety | Safety system isolation SP 800-82 ARCH-4 The safety instrumented system is separated from the control system and every other network. |
| Asset owner duty where the zone class is cell,line | Field devices in a cell or line zone SP 800-82 IAM-4 · PHYS-1 Where a controller has little or no logical authentication, the key switch, the locked cabinet and the seal are the control. |
| Asset owner duty where the family is utility | Building and utility plant SP 800-82 SECTOR-2 Building and utility systems share the characteristics of the line and are the ones most often left on the corporate network. |
| On the register as a whole | SP 800-82 ARCH-1 · GOV-3 · MON-2 · REC-1 |
The OT overlay
SP 800-82 is guidance, not a legal duty, and it is what an OT security programme is assessed against. On the register it is the overlay on the IEC 62443 rows: zones and conduits and the industrial DMZ, remote access through a brokered and recorded path with vendor accounts enabled just in time, patching tested in a representative environment with compensating controls where it cannot be done, and an incident plan with OT scenarios. Safety instrumented systems are isolated from everything else.
The clauses, quoted
15 of 48 in the frameworkRequirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
SP 800-82 MON-2 Asset Inventory and VisibilityMaintain an accurate, current inventory of OT assets including firmware versions, network locations, owners, and criticality, supported by passive discovery tooling.
Common gap: Spreadsheet-only inventory, last updated years ago
Source framework: NIST SP 800-82 Rev 3
SP 800-82 GOV-3 Safety and Security IntegrationIntegrate cybersecurity risk management with functional safety processes so that security controls do not impair safety functions and safety hazards inform security requirements.
Common gap: Safety and security teams operate in silos
Source framework: NIST SP 800-82 Rev 3
SP 800-82 HOST-6 Configuration Change ManagementManage changes to OT configurations, software, and firmware through documented approval, testing, version control, and rollback procedures.
Common gap: Undocumented PLC logic changes
Source framework: NIST SP 800-82 Rev 3
SP 800-82 HOST-4 Patch Management for OTEstablish an OT patch management process that tests patches in a representative environment, schedules deployment during maintenance windows, and applies compensating controls when patching is not feasible.
Common gap: No OT patch lab
Source framework: NIST SP 800-82 Rev 3
SP 800-82 IR-1 OT Incident Response PlanDevelop and maintain an incident response plan that addresses OT-specific scenarios, integrates with safety and emergency procedures, and includes communications with regulators and vendors.
Common gap: IT plan reused with no OT scenarios
Source framework: NIST SP 800-82 Rev 3
SP 800-82 ARCH-1 Network Segmentation by Zones and ConduitsSegment OT networks into logical zones and conduits aligned with the Purdue model and IEC 62443, restricting traffic between zones via controlled conduits with documented data flows.
Common gap: Flat OT network
Source framework: NIST SP 800-82 Rev 3
SP 800-82 ARCH-2 Industrial Demilitarised Zone (IDMZ)Implement an Industrial DMZ between the enterprise (IT) and control (OT) networks to terminate and inspect traffic, prevent direct connections, and host shared services such as patch repositories and historians replicas.
Common gap: Direct IT to OT connections bypassing IDMZ
Source framework: NIST SP 800-82 Rev 3
SP 800-82 NET-1 OT Firewall ConfigurationConfigure firewalls between OT zones with explicit deny-by-default policies, granular allowlists for required protocols, logging, and periodic rule review.
Common gap: Any-any rules between zones
Source framework: NIST SP 800-82 Rev 3
SP 800-82 RA-1 Secure Remote AccessProvide remote access to OT only via authenticated, encrypted, and brokered pathways such as jump hosts with multi-factor authentication, session recording, and time-bounded access.
Common gap: Direct VPN into OT
Source framework: NIST SP 800-82 Rev 3
SP 800-82 RA-2 Vendor Remote Access ControlsManage vendor remote access through individually identified accounts, contractual obligations, just-in-time enablement, supervision, and full logging.
Common gap: Always-on vendor tunnels
Source framework: NIST SP 800-82 Rev 3
SP 800-82 ARCH-4 Safety Instrumented System IsolationIsolate Safety Instrumented Systems (SIS) from the Basic Process Control System (BPCS) and other networks using physical or logical separation to preserve the integrity of safety functions.
Common gap: SIS sharing network with BPCS without separation
Source framework: NIST SP 800-82 Rev 3
SP 800-82 IAM-4 Physical Authentication for Field DevicesUse physical controls such as key switches, locked cabinets, and tamper-evident seals when logical authentication on field devices is limited or absent.
Common gap: PLCs left in RUN/REM allowing remote programming
Source framework: NIST SP 800-82 Rev 3
SP 800-82 PHYS-1 Physical Access Control to OT AssetsRestrict physical access to OT areas, control rooms, network closets, and field cabinets using authenticated entry controls and visitor management.
Common gap: Shared badges
Source framework: NIST SP 800-82 Rev 3
SP 800-82 SECTOR-2 Building Automation System SecurityApply OT security principles to building automation systems (HVAC, lighting, access control, elevators) that share many characteristics with industrial control systems.
Common gap: BAS on flat corporate network
Source framework: NIST SP 800-82 Rev 3
SP 800-82 REC-1 OT Backup and RestorationMaintain offline, integrity-checked backups of OT configurations, PLC logic, HMI projects, and historian data, with tested restoration procedures.
Common gap: Backups only on same network as systems
Source framework: NIST SP 800-82 Rev 3
See what it attaches to your list
Paste the equipment list, tick the regime, and every asset it reaches carries these rows. Eight assets free, no account.
Build my cell register