← Course Home Moraine Valley Community College · NCyTE  |  Instructor: Dr. John L. Sands

OT-101 · Day 4 · Lesson 8 · 4 contact hours

Frameworks for OT Security

Four standards claim the same territory. This lesson shows you where they actually overlap, where they genuinely differ, and how to choose one spine for your course instead of teaching all four at once.

Level: Intermediate Strand: Frameworks Duration: 4 hours 6 learning objectives

Lesson Overview

Orientation, anchoring analogy, and what you should be able to do by the end.

15 min

Faculty who start building an OT security course almost always hit the same wall: there are four widely cited bodies of guidance — IEC 62443, NIST SP 800-82, the NIST Cybersecurity Framework (CSF), and ISO/IEC 27001 — and they all sound authoritative, they all use overlapping vocabulary, and none of them announces which one a course should be built around. The usual result is a syllabus that samples all four, confuses students, and produces graduates who can name standards but cannot apply one.

This lesson takes the opposite approach. We treat the four documents as tools with different jobs, learn the internal logic of the one that is genuinely OT-native (IEC 62443), and then use the others as supporting material rather than competing curricula. By the end you will have drafted a one-page crosswalk you can hand to your own students.

Anchoring analogy — the building trades

Think about constructing a hospital. The zoning ordinance decides what may be built where and how areas are separated — that is IEC 62443, which partitions a plant into zones and controls what crosses between them. The engineering handbook for that specific building type gives detailed, sector-aware practice notes — that is NIST SP 800-82. The executive summary the hospital board reads, written so a non-engineer can ask sensible questions about risk, is NIST CSF. And the accreditation program that audits whether the hospital runs a disciplined management system, with documented policies and internal reviews, is ISO/IEC 27001.

All four describe the same hospital. Only one of them tells the contractor where to put the walls. Hold onto that distinction — it drives every decision in this lesson.

Learning objectives

By the end of this 4-hour session, you will be able to:

  1. Explain the scope, intended audience, and structure of IEC 62443, NIST SP 800-82 Rev. 3, NIST CSF 2.0, and ISO/IEC 27001, and state the job each one does best.
  2. Identify zones and conduits in a given plant network description and justify each boundary in terms of shared risk and required communication.
  3. Differentiate target, capability, and achieved Security Levels (SL-T, SL-C, SL-A) and assign an SL-T to a zone with written rationale.
  4. Compare the four frameworks across scope, unit of analysis, certification pathway, and classroom usability using a structured comparison.
  5. Evaluate which framework should serve as the spine of a specific course, given a program's constraints, and defend the choice.
  6. Design a one-page student-facing framework crosswalk that maps supporting standards onto your chosen spine.
Safeguards & Responsible Use. Nothing in this lesson touches live or production equipment, energized panels, or any real network. All hands-on work is browser-based simulation or isolated bench hardware. We study defense, not offensive tooling. Real incidents appear as case studies for analysis, never as step-by-step procedures. No vendor, employer, or customer data appears in any example — every plant, asset tag, and IP address below is fictional.
Part A

The Four Frameworks — What Each One Actually Does

Roughly 2 hours of guided lecture, diagrams, and worked examples.

1. The Landscape: Why There Are Four

Different authors, different customers, different units of analysis.

20 min

The four documents exist because four different communities needed something. Understanding who wrote each one and for whom resolves most of the apparent conflict between them.

  • IEC 62443 is a multi-part series developed through ISA99 and published jointly by ISA and the IEC. Its customer is the industrial automation and control system (IACS) community: asset owners, system integrators, and product suppliers. Its unit of analysis is the system under consideration (SUC) — a defined piece of a plant — broken into zones and conduits.
  • NIST SP 800-82 is a U.S. federal special publication, now in Revision 3 (2023), titled Guide to Operational Technology (OT) Security. Its customer is anyone who has to apply general-purpose security controls (NIST SP 800-53) to OT without breaking the process. Its unit of analysis is the control overlay: which of the general controls apply, how they must be tailored, and what to do when they cannot be applied.
  • NIST CSF, now at version 2.0 (2024), is not a control catalog at all. It is an outcome-based common language organized into six Functions: Govern, Identify, Protect, Detect, Respond, Recover. Its customer is leadership and cross-organizational communication. Its unit of analysis is the outcome ("Assets are managed consistently with their criticality"), deliberately silent on how you achieve it.
  • ISO/IEC 27001 is a certifiable international standard for an Information Security Management System (ISMS). Its customer is an organization that must demonstrate governance discipline to auditors, insurers, or trading partners. Its unit of analysis is the management system: scope, risk process, Statement of Applicability, internal audit, management review.
Four frameworks positioned by altitude and specificity A horizontal band chart. From top to bottom: ISO/IEC 27001 at the organization layer, NIST CSF 2.0 at the leadership communication layer, NIST SP 800-82 at the OT control tailoring layer, and IEC 62443 at the plant engineering layer. An arrow on the left labelled "increasing altitude, decreasing engineering detail" points upward. Organizational altitude → ISO/IEC 27001 — the management system Certifiable governance: scope, risk process, Statement of Applicability, audit, review NIST CSF 2.0 — the common language Six Functions: Govern, Identify, Protect, Detect, Respond, Recover. Outcomes, not methods. NIST SP 800-82 Rev. 3 — the OT tailoring guide How to apply SP 800-53 controls to OT without harming safety or availability IEC 62443 — the plant engineering standard Zones, conduits, Security Levels, foundational requirements, product and integrator roles
Figure 1. The four frameworks stacked by organizational altitude. ISO/IEC 27001 governs the organization; NIST CSF 2.0 gives leadership a shared vocabulary; NIST SP 800-82 Rev. 3 tailors general controls for OT; IEC 62443 specifies plant engineering in zones, conduits, and Security Levels. Nothing in the stack contradicts anything else — each layer answers a different question.
Teaching note. Students often assume newer means better, and that CSF 2.0 therefore supersedes 62443. It does not. CSF 2.0 has no concept of a PLC, a conduit, or a safety instrumented system. Say this explicitly on day one of your own course or you will spend the rest of the term correcting it.

2. IEC 62443: Zones and Conduits

The core structural idea of the whole series, and the one worth teaching first.

30 min

A zone is a grouping of logical or physical assets that share common security requirements. A conduit is the controlled communication path between zones — and critically, a conduit is itself a special kind of zone whose only members are the communication assets. Partitioning happens in IEC 62443-3-2, which defines the risk assessment process; the technical requirements those zones then inherit live in IEC 62443-3-3 (system requirements) and IEC 62443-4-2 (component requirements).

Two rules drive nearly every partitioning decision students will make:

  1. Group by shared risk, not by network topology. Two devices on the same VLAN may belong in different zones if their consequence of compromise differs sharply.
  2. Separate assets performing safety functions. IEC 62443-3-2 requires that safety-related assets be placed in a zone separate from non-safety assets. A safety instrumented system does not share a zone with basic process control just because they sit in the same cabinet.
Analogy — the ship's bulkheads

A ship is not one hollow hull. It is divided into watertight compartments so a breach in one does not sink the vessel, and the openings between compartments are deliberate, few, and closable. Zones are compartments. Conduits are the hatches. The security question is never "is the hull strong?" but "if this compartment floods, what else floods with it, and can I close the hatch in time?"

Worked example — Meridian Water District, Pump Station 4

A fictional municipal water utility operates a pump station with the following assets. Read it the way an assessor would: consequence first, wiring second.

Table 1. Asset inventory for the Pump Station 4 system under consideration (fictional).
Asset tagDescriptionCommunicationsConsequence of compromise
PLC-401Allen-Bradley-class controller, lead/lag pump sequencingEtherNet/IP to HMI; Modbus/TCP to VFDsLoss of pressure to 4,000 service connections
HMI-401Operator workstation, Windows-based, local to stationEtherNet/IP to PLC-401; historian feed northboundOperator blindness; possible unsafe manual commands
VFD-401A/BVariable frequency drives, 150 hp pumpsModbus/TCP, register-level controlMechanical damage, water hammer
SIS-401Safety controller: over-pressure trip and dry-run protectionHardwired trip; read-only diagnostics over serial gatewayPipe rupture, pump destruction, potential injury
HIST-CORPPlant historian, corporate data centerOPC UA northbound to business analyticsLoss of reporting; no direct process impact
RTU-VENDORCellular RTU used by the pump vendor for remote diagnosticsDNP3 over vendor-managed cellular linkThird-party path into the control network

A defensible partition looks like this. Note that SIS-401 gets its own zone even though it lives in the same building, and that the vendor's cellular RTU is not allowed to be "just another device on the control LAN":

Zone and conduit partition for Pump Station 4 A five-zone diagram arranged vertically. At the top, the Enterprise Zone contains the corporate historian and business analytics. Below it, an Operations DMZ Zone contains a replicated historian and a jump host, and is the only path between enterprise and control. Below that, the Supervisory Zone contains the operator HMI. Below that, the Control Zone contains the pump PLC and two variable frequency drives. To the right and fully separate, the Safety Zone contains the safety controller with a one-way diagnostic path only. A sixth box on the right, the Vendor Remote Access Zone, connects only into the Operations DMZ, never directly to control. Labelled conduits connect Enterprise to DMZ, DMZ to Supervisory, Supervisory to Control, Control to Safety as read-only, and Vendor to DMZ. Enterprise Zone HIST-CORP historian · business analytics · SL-T 1 Conduit C1 · OPC UA, DMZ-terminated Operations DMZ Zone Replicated historian · brokered jump host · no pass-through · SL-T 2 Conduit C2 · brokered sessions only Supervisory Zone HMI-401 operator workstation · SL-T 2 Conduit C3 · EtherNet/IP, allow-listed Control Zone PLC-401 · VFD-401A · VFD-401B · Modbus/TCP internal SL-T 3 Safety Zone SIS-401 over-pressure & dry-run trip SL-T 3 · hardwired trip path Conduit C4 · diagnostics, read-only outbound Vendor Remote Access Zone RTU-VENDOR · DNP3 over cellular SL-T 2 · terminates in DMZ only Conduit C5 · vendor path, never direct to control Six assets → five zones → five conduits. Every arrow is a decision that must be justified in the assessment record.
Figure 2. Zone and conduit partition for the fictional Pump Station 4. Reading top to bottom: the Enterprise Zone (SL-T 1) reaches the Operations DMZ (SL-T 2) through conduit C1 carrying OPC UA, which terminates in the DMZ rather than passing through. The DMZ reaches the Supervisory Zone (SL-T 2, HMI-401) through conduit C2, which permits brokered sessions only. The Supervisory Zone reaches the Control Zone (SL-T 3, PLC-401 and both VFDs) through conduit C3 with allow-listed EtherNet/IP. The Safety Zone (SL-T 3, SIS-401) is physically separate and exposes only a read-only outbound diagnostics conduit, C4; its trip function is hardwired and does not depend on the network. The Vendor Remote Access Zone (SL-T 2, RTU-VENDOR) connects only to the DMZ through conduit C5 and has no direct path to the Control Zone.
Why the vendor RTU gets its own zone. It has a different owner, a different patch cycle, a different authentication authority, and a communication path the utility does not control. Under the "shared security requirements" test, it fails to belong with anything else in the station. This is the single most useful partitioning question you can teach: who else must I trust if I put these two assets together?

3. Security Levels: SL-T, SL-C, and SL-A

The most misunderstood idea in 62443 — and the most testable.

25 min

A Security Level in IEC 62443 is not a maturity score for an organization. It is a statement about the capability of an adversary that a zone or component is expected to withstand, expressed on a 0-to-4 scale and evaluated against seven foundational requirements (FR 1 through FR 7): identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability.

Table 2. IEC 62443 Security Levels described by adversary capability.
LevelProtects againstAdversary profilePlausible plant example
SL 0No specific requirementNone statedAn isolated display with no consequence of compromise
SL 1Casual or coincidental violationAn untrained person clicking the wrong thingA conference-room dashboard on a read-only feed
SL 2Intentional violation using simple meansLow resources, generic skills, low motivationSupervisory HMI zone; operations DMZ
SL 3Intentional violation using sophisticated meansModerate resources, IACS-specific skills, moderate motivationControl zone with pump PLC; safety zone
SL 4Intentional violation using sophisticated means with extended resourcesExtended resources, IACS-specific skills, high motivationNational-scale transmission or nuclear-adjacent systems

The three flavours students confuse

Each card is a button: press Enter or Space to flip it. All four definitions also print in full.

Worked example — reading an SL gap

Back at Pump Station 4, the assessment team sets SL-T 3 for the Control Zone. They then inventory what is actually installed:

  • PLC-401 ships with SL-C 2 for FR 1 (identification and authentication control) — it supports a single shared engineering password, not per-user accounts.
  • The VFDs accept unauthenticated Modbus/TCP writes to their speed-reference registers. Modbus/TCP has no authentication in the protocol at all, so FR 1 capability at the component level is effectively SL-C 0.
  • The zone therefore achieves roughly SL-A 1 for FR 1 against a target of SL 3.

The gap is not closed by buying a firewall and declaring victory. Realistic compensating measures, in the order an engineer would consider them, are: move VFD control behind the PLC so no supervisory device writes Modbus registers directly; enforce per-user authentication at the conduit through a brokered jump host; and add monitoring that alarms on any Modbus write function code (function 6 or 16) originating outside the Control Zone. Documenting the residual gap is itself a valid outcome — 62443 expects an assessment record, not a perfect score.

Assessment idea. Give students an inventory with stated SL-C values and a target SL-T, and ask for the gap table plus one compensating measure per gap. It marks quickly, it cannot be answered by memorization, and it mirrors real assessment work almost exactly.

4. NIST SP 800-82 Rev. 3 and the Cybersecurity Framework

One tailors controls for OT; the other gives everyone a shared vocabulary.

25 min

NIST SP 800-82 Revision 3

Revision 3 broadened the title from "Industrial Control Systems" to "Operational Technology," reflecting that building automation, physical access control, and transportation systems face the same problem as a refinery. Its most classroom-useful contribution is the OT overlay: for each control family in NIST SP 800-53, it states whether the control applies to OT, how it must be tailored, and what compensating control to use when the standard approach would endanger the process.

Analogy — the field guide, not the map

If IEC 62443 is the zoning ordinance, SP 800-82 is the annotated field guide an experienced engineer hands you on your first day: "Yes, the corporate policy says patch within 30 days. Here is what that actually means when the vendor will void your safety certification and the next maintenance window is in eight months."

Worked example. Corporate policy mandates automatic screen lock after 10 minutes of inactivity. Applied literally to HMI-401 at Pump Station 4, an operator watching a developing over-pressure condition loses the screen at the worst moment. The SP 800-82 tailoring pattern is: keep the control's intent (prevent unauthorized use of an unattended console), change the implementation (physical access control to the operator room, session lock on the engineering workstation but not the alarm display, and camera coverage), and document the deviation with its rationale. Students should learn the phrase "the control's intent survives; the implementation is negotiable."

NIST CSF 2.0

CSF 2.0's headline change is the addition of GOVERN as a sixth Function, sitting alongside Identify, Protect, Detect, Respond, and Recover. Govern covers organizational context, risk management strategy, roles and responsibilities, policy, oversight, and — newly prominent — cybersecurity supply chain risk management.

The six Functions of NIST CSF 2.0 Govern is shown as a wide foundation bar beneath five equal blocks: Identify, Protect, Detect, Respond, and Recover. Govern underlies all five, indicating it informs every other Function rather than sitting in sequence with them. IDENTIFY Assets, risk PROTECT Safeguards DETECT Find events RESPOND Act on it RECOVER Restore GOVERN — new in CSF 2.0 Organizational context · risk strategy · roles & responsibilities · policy · oversight · supply chain risk
Figure 3. CSF 2.0's six Functions. Identify, Protect, Detect, Respond, and Recover sit in a row; GOVERN spans beneath all five because it informs each of them rather than following them in sequence. Govern covers organizational context, risk management strategy, roles and responsibilities, policy, oversight, and cybersecurity supply chain risk management.

For an OT course, CSF's value is communicative rather than technical. A plant manager who will never read IEC 62443-3-3 will happily discuss whether the site is weak on DETECT. Use CSF as the reporting surface and 62443 as the engineering underneath.

5. ISO/IEC 27001 and the Management System

The one that gets audited — and the one most OT courses can safely keep small.

20 min

ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System. Its numbered clauses (context, leadership, planning, support, operation, performance evaluation, improvement) are the certifiable part; Annex A lists reference controls, organized in the 2022 edition into four themes — organizational, people, physical, and technological. Detailed implementation guidance lives in the companion standard ISO/IEC 27002.

Analogy — the kitchen inspection

A health inspector visiting a restaurant does not taste the soup. They check that thermometers are calibrated on a schedule, that the temperature log has entries for every shift, that someone is accountable when a reading is out of range, and that last quarter's corrective actions were closed. ISO/IEC 27001 works the same way: it audits the system that produces security, not the security of any individual control. That is why an organization can hold a certificate and still have a badly configured PLC — the certificate speaks to process discipline within a declared scope.

Worked example — the scope statement trap. Meridian Water District's certificate reads "the ISMS covering corporate IT services delivered from the administration building." That scope excludes every pump station. A student who sees the certificate on the wall and concludes the SCADA network is covered has made exactly the mistake this lesson exists to prevent. Teach students to read the Statement of Applicability and the scope statement before they read anything else.

How much to teach. For most community college OT courses, ISO/IEC 27001 deserves one class period: what an ISMS is, what a scope statement and Statement of Applicability are, and why a certificate is not a security guarantee. Going deeper turns an OT course into an auditing course.

6. Side by Side

Overlap, difference, and classroom fit in one table.

20 min
Table 3. Comparing the four frameworks across the dimensions that matter for course design.
DimensionIEC 62443NIST SP 800-82 Rev. 3NIST CSF 2.0ISO/IEC 27001
Primary scopeIACS across its lifecycle: products, integration, operationApplying and tailoring security controls to OT environmentsAny organization's cybersecurity risk outcomesOrganizational information security management
Unit of analysisZone, conduit, system under considerationControl and its OT tailoringOutcome (Category / Subcategory)Management system within a declared scope
Native to OT?Yes — designed for itYes — an OT-specific guideNo — sector-neutralNo — IT-origin, applicable by scoping
Grading scaleSecurity Levels 0–4 per foundational requirementNone; uses SP 800-53 baselines (low / moderate / high)Tiers 1–4 describe rigor, not a scorePass / fail certification audit
CertificationProduct, process, and personnel certification schemes existNone — guidance onlyNone — voluntary frameworkAccredited organizational certification
Cost to studentsPurchase required for most parts; free explainers existFree downloadFree downloadPurchase required
Best classroom jobThe engineering spine: segmentation, requirements, design labsControl tailoring and safety-versus-security tradeoff discussionsExecutive reporting, program framing, cross-team languageGovernance vocabulary and audit literacy
Watch out forPart numbering confuses beginners; paywall limits assignmentsLong document; students skim instead of reading the overlayFeels complete but specifies no OT techniqueCertificate scope is routinely misread

Where they genuinely overlap

All four require you to know what you own, assess risk against consequence, apply proportionate controls, monitor, and improve. Roughly 70–80 percent of the activity is common; what differs is the vocabulary and the depth of engineering specificity. This is why teaching four at once is wasteful — you repeat the same activity four times in four dialects.

Where they genuinely differ

  • Only IEC 62443 gives you a repeatable method for partitioning a plant and expressing required adversary resistance per zone.
  • Only SP 800-82 systematically addresses what to do when a standard IT control would harm the process.
  • Only CSF 2.0 is designed to be readable by someone with no security background, which makes it the right artifact for a board slide.
  • Only ISO/IEC 27001 produces an auditable certificate, which is why procurement departments ask for it.
Part B

Hands-On — Partition, Map, and Choose

Roughly 2 hours of simulation and applied design work. Everything below runs in your browser.

7. Simulation: Zone & Conduit Planner

Assign each asset to a zone, then let the planner derive conduits and flag partitioning findings.

35 min

Simulation only — no live equipment, no network traffic, no real plant data.

This planner models the fictional Northline Bottling Plant, Line 2. Assign every asset to a zone, then choose Evaluate my partition. The tool derives the conduits your design implies and checks it against four IEC 62443-3-2 partitioning principles. It is deliberately opinionated: there is more than one defensible answer, and the findings are prompts for discussion, not a grade.

Northline Bottling Plant — Line 2 assets

Assign each asset to a zone, then choose Evaluate my partition. Results appear here.

Facilitator prompt. Run the planner twice. The first time, let participants place assets by network topology (everything on the plant LAN together). The second time, force them to ask "what is the consequence if this asset is compromised?" The change in the findings list is the whole lesson about grouping by shared risk rather than by switch port.

8. Mapping Lab: Which Framework Owns This Statement?

Six requirements. Match each to the framework that is genuinely its home.

25 min

Activity 8.1 — Framework provenance matching

25 minutes · pairs
Instructions. Each row states a requirement in the words a practitioner would use. Choose the framework where that requirement originates — not merely one that touches the topic. Several statements are echoed in more than one document, which is the point: you are looking for the home, not a mention.

Individual · 6 min

Answer all six on your own without discussion.

Pairs · 10 min

Compare with a partner. Argue any row where you disagree before checking.

Share · 9 min

Report the row your pair argued longest about. That row is usually the most teachable.
Table 4. Match each requirement to its framework of origin.
Requirement statementFramework of origin

9. Choosing One Spine for Your Course

A decision procedure, three defensible outcomes, and the artifact you will build.

35 min

A spine is the framework whose vocabulary and structure organize your syllabus. Everything else becomes a supporting reference introduced when it is needed. One spine, cited consistently, beats four surveyed.

Analogy — the textbook you adopt

You already do this. You adopt one textbook, then supplement with articles, a lab manual, and your own slides. Nobody assigns four textbooks and asks students to reconcile them. Framework selection is textbook adoption with higher stakes and worse marketing.

Decision procedure

  1. Name the graduate. What job title is the student walking into? A controls technician, an OT analyst in a SOC, or a compliance coordinator? The job decides the dialect.
  2. Check the constraints. Can students access the documents? IEC 62443 parts are paid; SP 800-82 and CSF are free downloads. This constraint is real and it shapes what you can assign.
  3. Check the downstream credential. If your program feeds into a certification pathway or an articulation agreement, align to whatever that pathway uses.
  4. Pick the spine, then demote the rest to references and write that decision into the syllabus so it survives adjunct turnover.
Table 5. Three defensible spine choices for community college programs.
If your program is…Use this spineBecauseBring in the others when…
An industrial maintenance or automation AAS adding a security courseIEC 62443Zones, conduits, and Security Levels map directly onto equipment students already touchSP 800-82 for the patching and availability tradeoff unit; CSF for the final capstone briefing
A cybersecurity AAS adding an OT electiveNIST SP 800-82 Rev. 3Students already know SP 800-53 language; the overlay teaches OT by contrast, and the document is freeIEC 62443 for the segmentation lab; CSF for governance framing
A short workforce or incumbent-worker certificateNIST CSF 2.0Six Functions are learnable in one session and give a shared vocabulary across mixed job rolesIEC 62443 zone concepts inside PROTECT; ISO 27001 named once under GOVERN

Activity 9.1 — Build your one-page crosswalk (assessment artifact)

30 minutes · individual, then gallery walk
Deliverable. One page, submitted as PDF or a single slide, that a student in your course could keep beside them all term.

Your crosswalk must contain:

  1. Your spine, named, with a two-sentence rationale that references your program's graduate profile and at least one real constraint (cost, access, articulation, contact hours).
  2. Your course's five or six major units listed in teaching order, each labelled with the spine's own terminology.
  3. One supporting reference per unit drawn from the other three frameworks, with a single sentence on what it adds that the spine does not.
  4. One "commonly confused" note — a place where two frameworks use similar words for different things (for example, "Security Level" in 62443 versus "Tier" in CSF), written in language your students will actually read.
  5. A safeguards line stating that all coursework is simulation or isolated-bench only.

Success criteria

  • A colleague can tell which framework is the spine within five seconds of looking at the page.
  • Every supporting reference has a stated reason to exist. No reference is listed "for completeness."
  • Terminology is consistent: you do not switch dialects between units.
  • The rationale would survive a curriculum committee asking "why not one of the other three?"

Gallery walk. Post your page. Read three others. On a sticky note, write the one question you would ask that author's curriculum committee.

10. Knowledge Check

Five questions. Feedback explains the reasoning, not just the letter.

15 min
1. A plant has a safety instrumented system and a basic process control system installed in the same cabinet, on the same switch. Under IEC 62443-3-2, what is the expected partitioning outcome?
2. A supplier's datasheet states the controller is "SL-C 3 for FR 1." What has the supplier actually claimed?
3. A department wants students to be able to argue, in front of a plant manager, that the site is weak at finding intrusions. Which framework provides the most appropriate vocabulary for that specific conversation?
4. An organization holds an ISO/IEC 27001 certificate. What may you safely conclude about its pump station SCADA network?
5. Corporate policy requires 10-minute inactivity screen lock. Applying it to an alarm display would blind operators during upsets. What does the NIST SP 800-82 Rev. 3 tailoring approach recommend?

Further Reading & Downloads

Primary sources cited in this lesson. External links open in a new tab.

Reference

Standards and framework pages

Standard series IEC 62443

The ISA landing page for the full series, including which parts address asset owners, integrators, and product suppliers.

Framework NIST CSF 2.0

The framework home page, with the Functions, informative references, and quick-start guides.

Standard ISO/IEC 27001

Official catalogue entry for the ISMS requirements standard.

Peer-reviewed article Security Aspects of Zones and Conduits in IEC 62443

A deeper treatment of partitioning decisions; useful as an assigned reading for the zone lab.

Downloadable documents

  • 📄 Download: NIST SP 800-82 Rev. 3 — Guide to Operational Technology (OT) Security. Assign the OT overlay section, not the whole document.
  • 📄 Download: NIST CSF 2.0 — the framework core, including the GOVERN Function.
  • 📄 Download: ISAGCA Quick Start Guide — a short orientation to the 62443 series, useful when the full parts are behind a paywall.
Draft status. This lesson page is a first AI-generated draft prepared for OT-101. It has not yet been reviewed by a human subject-matter expert. Verify every standard reference, part number, and technical claim against the primary sources above before using it with students.