Security About 2 min read

Security and assurance

Review the integration from its inputs through to the equipment it can affect. Record permissions, deployed versions, failure cases and the evidence supporting each control.

Overview#

This section turns protocol capabilities into defensible system properties. Encryption support alone doesn't make a deployment secure: identity, authorisation, commissioning, key lifecycle, failure behaviour, monitoring, recovery, and physical consequences all matter.

NIST includes physical access control, building automation, physical environment monitoring, and other cyber physical systems within operational technology, whose security must preserve performance, reliability, and safety NIST 800 82. At the 25 August 2026 baseline, Rev. 3 remains the final guide. NIST's Rev. 4 item is an Pre draft Call for Comments, published 22 January 2026; it is revision work, not a replacement final publication NIST 800 82 R4.

Start here#

Page Purpose Verification
Threat modelling and trust boundaries Model assets, actors, flows, abuse cases, and physical effects V2
Segmentation and conduits Isolate device, management, integration, and user planes V2
Identity and authorisation controls Apply identity and permission controls to people, devices, services, and commands V2
PKI, certificates, keys, and secrets Operate trust material through its full lifecycle V2
Secure commissioning and onboarding Establish device identity without permanent bootstrap weaknesses V2
Secure protocol parsing Build bounded, fail closed parsers and state machines V2
API and event security Protect commands, events, webhooks, and message brokers V2
Remote access Constrain support and administrative paths V2
Firmware and software supply chain Protect build, update, dependency, and provenance flows V2
Vulnerability management Triage advisories and coordinate remediation V2
Logging, time, and evidence integrity Preserve trustworthy audit and evidential context V2
Privacy and sensitive data Minimize exposure of surveillance, identity, and credential data V2
Resilience, backup, and recovery Design predictable degraded modes and recoverability V2
Secure system baselines Apply minimum controls by component role V2

Core invariants#

  • Treat observe, configure, administer, and actuate as different permission classes.
  • Authenticate both endpoints where feasible; authorise every operation independently of transport security.
  • Treat discovery, commissioning, time, update, and recovery paths as part of the attack surface.
  • Prefer deny by default network and application policy, with named and reviewable exceptions.
  • Preserve safe physical behaviour when networks, identity providers, clouds, certificates, or clocks fail.
  • Record exact model, firmware, protocol profile, secure mode configuration, and trust anchors before asserting security or interoperability.

Sources#