Cell Register
Standards ยท SP 800-82

NIST SP 800-82 Rev 3

Rendered when the buyer ticks "NIST SP 800-82 Rev 3". The register cites 16 of its 48 clauses, behind 7 findings: remote access into a cell or line zone, flat network: networked assets with no zone named, a wrong action reaches a person, no safety function noted, no change record on an adaptive or networked asset, end of support or unpatched, vendor share at or above a third, safety zone shares a conduit with a business asset, and on the obligation rows of every asset it reaches. Binds guidance addressed to the operator of the OT environment: it binds nobody in law and is what most OT security programmes are assessed against.

Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. Framework page. What it attaches on the register: the SP 800-82 regime page.

Clauses cited

16 of 48
SP 800-82 MON-2 Asset Inventory and Visibility

Maintain an accurate, current inventory of OT assets including firmware versions, network locations, owners, and criticality, supported by passive discovery tooling.

Evidence an auditor accepts: OT asset inventory export; Passive discovery tool configuration; Quarterly reconciliation evidence
Common gap: Spreadsheet-only inventory, last updated years ago
Source framework: NIST SP 800-82 Rev 3
SP 800-82 GOV-3 Safety and Security Integration

Integrate cybersecurity risk management with functional safety processes so that security controls do not impair safety functions and safety hazards inform security requirements.

Evidence an auditor accepts: Combined safety/security risk register; HAZOP or LOPA outputs referenced by security plan; Cyber-physical impact analysis
Common gap: Safety and security teams operate in silos
Source framework: NIST SP 800-82 Rev 3
SP 800-82 HOST-6 Configuration Change Management

Manage changes to OT configurations, software, and firmware through documented approval, testing, version control, and rollback procedures.

Evidence an auditor accepts: Change advisory board records; Configuration baselines per device; Version control for PLC logic
Common gap: Undocumented PLC logic changes
Source framework: NIST SP 800-82 Rev 3
SP 800-82 HOST-4 Patch Management for OT

Establish an OT patch management process that tests patches in a representative environment, schedules deployment during maintenance windows, and applies compensating controls when patching is not feasible.

Evidence an auditor accepts: OT patch policy; Patch test lab evidence; Patch deployment records
Common gap: No OT patch lab
Source framework: NIST SP 800-82 Rev 3
SP 800-82 IR-1 OT Incident Response Plan

Develop and maintain an incident response plan that addresses OT-specific scenarios, integrates with safety and emergency procedures, and includes communications with regulators and vendors.

Evidence an auditor accepts: OT IR plan; Scenario playbooks; Contact list including vendors and regulators
Common gap: IT plan reused with no OT scenarios
Source framework: NIST SP 800-82 Rev 3
SP 800-82 ARCH-1 Network Segmentation by Zones and Conduits

Segment OT networks into logical zones and conduits aligned with the Purdue model and IEC 62443, restricting traffic between zones via controlled conduits with documented data flows.

Evidence an auditor accepts: Zone and conduit diagram; Purdue level mapping; Conduit data flow matrix
Common gap: Flat OT network
Source framework: NIST SP 800-82 Rev 3
SP 800-82 ARCH-2 Industrial Demilitarised Zone (IDMZ)

Implement an Industrial DMZ between the enterprise (IT) and control (OT) networks to terminate and inspect traffic, prevent direct connections, and host shared services such as patch repositories and historians replicas.

Evidence an auditor accepts: IDMZ architecture diagram; List of services hosted in IDMZ; Firewall rule sets terminating connections in IDMZ
Common gap: Direct IT to OT connections bypassing IDMZ
Source framework: NIST SP 800-82 Rev 3
SP 800-82 NET-1 OT Firewall Configuration

Configure firewalls between OT zones with explicit deny-by-default policies, granular allowlists for required protocols, logging, and periodic rule review.

Evidence an auditor accepts: Firewall rule export; Quarterly rule review records; Deny-by-default baseline
Common gap: Any-any rules between zones
Source framework: NIST SP 800-82 Rev 3
SP 800-82 RA-1 Secure Remote Access

Provide remote access to OT only via authenticated, encrypted, and brokered pathways such as jump hosts with multi-factor authentication, session recording, and time-bounded access.

Evidence an auditor accepts: Remote access policy; Jump host configuration; MFA enforcement records
Common gap: Direct VPN into OT
Source framework: NIST SP 800-82 Rev 3
SP 800-82 RA-2 Vendor Remote Access Controls

Manage vendor remote access through individually identified accounts, contractual obligations, just-in-time enablement, supervision, and full logging.

Evidence an auditor accepts: Vendor remote access agreements; Just-in-time enablement procedure; Supervision logs
Common gap: Always-on vendor tunnels
Source framework: NIST SP 800-82 Rev 3
SP 800-82 ARCH-4 Safety Instrumented System Isolation

Isolate Safety Instrumented Systems (SIS) from the Basic Process Control System (BPCS) and other networks using physical or logical separation to preserve the integrity of safety functions.

Evidence an auditor accepts: SIS network diagram; Documented separation method; Change records for SIS connections
Common gap: SIS sharing network with BPCS without separation
Source framework: NIST SP 800-82 Rev 3
SP 800-82 IAM-4 Physical Authentication for Field Devices

Use physical controls such as key switches, locked cabinets, and tamper-evident seals when logical authentication on field devices is limited or absent.

Evidence an auditor accepts: Cabinet lock inventory; Key switch position policy; Tamper seal logs
Common gap: PLCs left in RUN/REM allowing remote programming
Source framework: NIST SP 800-82 Rev 3
SP 800-82 PHYS-1 Physical Access Control to OT Assets

Restrict physical access to OT areas, control rooms, network closets, and field cabinets using authenticated entry controls and visitor management.

Evidence an auditor accepts: Access control system records; Visitor logs; Cabinet key inventory
Common gap: Shared badges
Source framework: NIST SP 800-82 Rev 3
SP 800-82 SECTOR-2 Building Automation System Security

Apply OT security principles to building automation systems (HVAC, lighting, access control, elevators) that share many characteristics with industrial control systems.

Evidence an auditor accepts: BAS asset inventory; Segmentation from corporate IT; Vendor remote access controls for BAS
Common gap: BAS on flat corporate network
Source framework: NIST SP 800-82 Rev 3
SP 800-82 REC-1 OT Backup and Restoration

Maintain offline, integrity-checked backups of OT configurations, PLC logic, HMI projects, and historian data, with tested restoration procedures.

Evidence an auditor accepts: Backup inventory; Offline copy storage records; Restoration test logs
Common gap: Backups only on same network as systems
Source framework: NIST SP 800-82 Rev 3
SP 800-82 RM-2 Supply Chain Risk Management

Manage supply chain risks for OT including vendor security assessment, secure procurement language, software bill of materials, and ongoing monitoring of third parties.

Evidence an auditor accepts: Vendor risk assessments; Procurement security clauses; SBOM repository
Common gap: No security clauses in OT procurement
Source framework: NIST SP 800-82 Rev 3

See which clauses your list engages

Paste the list and every asset names the clauses behind it, filtered to the regimes that apply to you. Eight assets free, no account.

Build my cell register