Security and assurance
Review the integration from its inputs through to the equipment it can affect. Record permissions, deployed versions, failure cases and the evidence supporting each control.
On this page
Overview#
This section turns protocol capabilities into defensible system properties. Encryption support alone doesn't make a deployment secure: identity, authorisation, commissioning, key lifecycle, failure behaviour, monitoring, recovery, and physical consequences all matter.
NIST includes physical access control, building automation, physical environment monitoring, and other cyber physical systems within operational technology, whose security must preserve performance, reliability, and safety NIST 800 82. At the 25 August 2026 baseline, Rev. 3 remains the final guide. NIST's Rev. 4 item is an Pre draft Call for Comments, published 22 January 2026; it is revision work, not a replacement final publication NIST 800 82 R4.
Start here#
| Page | Purpose | Verification |
|---|---|---|
| Threat modelling and trust boundaries | Model assets, actors, flows, abuse cases, and physical effects | V2 |
| Segmentation and conduits | Isolate device, management, integration, and user planes | V2 |
| Identity and authorisation controls | Apply identity and permission controls to people, devices, services, and commands | V2 |
| PKI, certificates, keys, and secrets | Operate trust material through its full lifecycle | V2 |
| Secure commissioning and onboarding | Establish device identity without permanent bootstrap weaknesses | V2 |
| Secure protocol parsing | Build bounded, fail closed parsers and state machines | V2 |
| API and event security | Protect commands, events, webhooks, and message brokers | V2 |
| Remote access | Constrain support and administrative paths | V2 |
| Firmware and software supply chain | Protect build, update, dependency, and provenance flows | V2 |
| Vulnerability management | Triage advisories and coordinate remediation | V2 |
| Logging, time, and evidence integrity | Preserve trustworthy audit and evidential context | V2 |
| Privacy and sensitive data | Minimize exposure of surveillance, identity, and credential data | V2 |
| Resilience, backup, and recovery | Design predictable degraded modes and recoverability | V2 |
| Secure system baselines | Apply minimum controls by component role | V2 |
Core invariants#
- Treat observe, configure, administer, and actuate as different permission classes.
- Authenticate both endpoints where feasible; authorise every operation independently of transport security.
- Treat discovery, commissioning, time, update, and recovery paths as part of the attack surface.
- Prefer deny by default network and application policy, with named and reviewable exceptions.
- Preserve safe physical behaviour when networks, identity providers, clouds, certificates, or clocks fail.
- Record exact model, firmware, protocol profile, secure mode configuration, and trust anchors before asserting security or interoperability.
Sources#
- NIST 800 82, NIST SP 800-82 Rev. 3: Guide to Operational Technology Security, final September 2023, accessed 25 August 2026.
- NIST 800 82 R4, NIST SP 800-82 Rev. 4 Pre draft Call for Comments, pre draft call published 22 January 2026, accessed 25 August 2026.
- NIST SSDF, NIST SP 800-218: Secure Software Development Framework Version 1.1, final February 2022, accessed 25 August 2026.