OT

Teaching Operational Technologies

Core Frameworks โ€” Student Guide

โ† Course Navigation
U.S. Federal Guide ยท Risk Management

NIST SP 800-82 Rev. 3 โ€” Guide to Operational Technology (OT) Security

A student's walk-through of NIST's flagship OT security guide: how it's organized, what changed in the 2023 rewrite, its risk-management process, its architecture guidance, and the SP 800-53 overlays that turn it into an actual control baseline.

โ† Back to Course Navigation

Quick Facts

Type
U.S. federal guidance document
Publisher
NIST, Computer Security Resource Center
Current Version
Revision 3 (2023)
Scope
All OT โ€” ICS, building automation, physical access control
Built On
SP 800-53 Rev. 5 controls, tailored via overlays
Primary Use
OT risk management baseline, free and vendor-neutral
01

Foundations

02

How to Use This Guide

  1. 1

    Skim the Quick Facts panel first. The scope line โ€” "all OT," not just ICS โ€” is the single fact that most separates Rev. 3 from everything that came before it.

  2. 2

    Read Section 03 before the structure itself. Seeing how SP 800-82 differs from IEC 62443, ATT&CK for ICS, and CIP-008 makes its risk-management framing easier to place.

  3. 3

    Work through Section 04's four pillar cards in order โ€” Understand โ†’ Manage Risk โ†’ Architect โ†’ Align. They follow the guide's own chapter progression from OT fundamentals through to the SP 800-53 overlays.

  4. 4

    Treat Section 05 as a lookup, not a read-through. Terms like "overlay" and "tailoring" get reused constantly once you reach Section 04.3 โ€” come back here when one is unfamiliar.

  5. 5

    If you're prepping to teach, start at Section 08. The Overlay Tailoring Drill is the exercise most students find clarifies the whole guide at once.

03

Positioning: SP 800-82 vs. the Other Core Frameworks

IEC 62443 is a standalone, certifiable design standard. ATT&CK for ICS is a descriptive threat-intelligence knowledge base. CIP-008 is a mandatory sector regulation. SP 800-82 sits in a fourth position: voluntary federal guidance that pulls an organization's OT risk management into the same ecosystem as its IT risk management.

AttributeNIST SP 800-82 Rev. 3IEC 62443 / ATT&CK for ICS / CIP-008
TypeFederal risk-management guidanceCertifiable design standard, threat-intel knowledge base, or mandatory sector regulation
Origin / AuthorityNIST, a U.S. federal standards bodyISA/IEC standards body, MITRE (federally funded R&D), NERC (the ERO, under FERC)
Primary Question"How do I manage OT risk using the same control catalog and process my IT team already uses?""How should this be designed?", "What has been done to systems like this?", or "What must I legally report?"
EnforcementRequired for U.S. federal agencies via FISMA/RMF; voluntary elsewhereCertification (62443), none (ATT&CK for ICS), or legal penalty (CIP-008)
Typical PairingSupplies the risk-management and control-baseline layer that the others plug into62443 supplies the zones/conduits vocabulary; ATT&CK for ICS supplies the threat data; CIP-008 supplies the reporting obligation once a risk becomes an incident
04

Structure & Overlays

SP 800-82 Rev. 3 reads as four pillars building on each other: understand what OT actually is, manage risk against it, architect a defense, and align that defense to the broader NIST control ecosystem. The colors below deliberately reuse this site's existing strand colors โ€” Understand borrows the orange used for "Foundations," Manage Risk borrows the purple used for "Frameworks," Architect borrows the blue used for "Protocols," and Align borrows the green used for "Operations."

Ch. 1โ€“2Understand
OT Overview
What OT is, how it differs from IT, and the full range of systems Rev. 3 now covers.
Ch. 3Manage Risk
OT Risk Management
A risk process tailored to OT's safety- and availability-first priorities, and the threats/vulnerabilities specific to it.
Ch. 4Architect
Cybersecurity Architecture
Reference network architectures, defense-in-depth, segmentation, and boundary protection patterns for OT.
Ch. 5 + App.Align
Frameworks & Overlays
Mapping to the NIST Cybersecurity Framework, and the SP 800-53 overlays that turn all of this into a selectable control baseline.

Pillar 1 โ€” Understand OT

Pillar 2 โ€” Manage Risk

Pillar 3 โ€” Architect Defense

Pillar 4 โ€” Align to Frameworks & Controls

05

Definitions & Scope

These terms come directly from the broader NIST risk-management vocabulary that SP 800-82 inherits and tailors.

Operational Technology (OT)

Hardware and software that detects or causes changes in physical processes through direct monitoring or control โ€” the Rev. 3 scope, wider than "ICS."

Industrial Control System (ICS)

The classic subset of OT โ€” SCADA, DCS, and PLC-based systems controlling industrial processes โ€” that Rev. 1 and Rev. 2 focused on exclusively.

Overlay

A pre-tailored, specialized set of security controls, control enhancements, and supplemental guidance for a particular type of system or environment โ€” here, OT at a given impact tier.

Security Control Baseline

The starting set of controls associated with a system's impact level (Low, Moderate, High) before any further tailoring is applied.

Tailoring

The documented process of adjusting a control baseline โ€” adding, removing, or modifying controls โ€” to fit an actual environment's constraints.

Compensating Control

An alternative safeguard used when the originally specified control can't be implemented as written โ€” the standard response to OT's patch and legacy constraints.

Risk Management Framework (RMF)

NIST SP 800-37's overall process โ€” categorize, select, implement, assess, authorize, monitor โ€” that SP 800-82's OT risk chapter follows and tailors.

System Security Plan (SSP)

The document that records which controls apply to a system and how they're implemented โ€” where an OT overlay's selections ultimately get written down.

06

Related NIST Resources

SP 800-82 doesn't stand alone โ€” it's one node in NIST's much larger risk-management publication set, and it borrows structure and vocabulary from several others.

ResourceFocusHow It Connects to SP 800-82
SP 800-53 Rev. 5The base security & privacy control catalogThe catalog that SP 800-82's OT overlays tailor for Low/Moderate/High-impact OT
NIST Cybersecurity Framework 2.0Outcome-based function structureThe Govern/Identify/Protect/Detect/Respond/Recover functions SP 800-82's risk activities are mapped onto
SP 800-37Risk Management Framework (RMF)The overall categorize-select-implement-assess-authorize-monitor process SP 800-82's OT risk chapter follows
SP 800-30Guide for Conducting Risk AssessmentsThe general risk-assessment methodology that SP 800-82 tailors for OT-specific threat sources and impact
NIST SP 1800 SeriesNCCoE practice guidesSector-specific, hands-on implementation examples that show SP 800-82 guidance applied to real reference architectures
07

Adoption & Practical Use

SP 800-82 occupies a middle ground between CIP-008's legal mandate and ATT&CK for ICS's total lack of enforcement: it is required for U.S. federal agencies through FISMA-driven RMF processes, and voluntarily โ€” but very widely โ€” adopted everywhere else.

Federal Agencies

Required as the OT-specific control reference within FISMA-driven Risk Management Framework processes for federal OT-adjacent systems.

Critical Infrastructure Operators

Adopted voluntarily as a free, vendor-neutral OT security reference โ€” often the first document a new OT security hire is handed.

Auditors & Assessors

Used as a control-mapping reference when assessing an OT environment against the SP 800-53 catalog it tailors.

Vendors & Integrators

Cited directly in RFPs and contracts as the expected control baseline for a delivered OT system, especially in the public sector.

๐Ÿ“– Teaching Note

Anchor lesson: Lesson 8 (Frameworks for OT Security) and Lesson 9 (Governance, Risk & Compliance). For the "pick one spine instead of four" discussion in Lesson 8, have students open the OT overlay appendix and select five controls to map against a fictional plant; in Lesson 9, have them write POA&M entries for a control that isn't feasible.

08

Classroom Uses

Overlay Tailoring Drill

Give students five controls from an OT overlay baseline and a fictional plant scenario. For each, they decide: implement as-is, tailor, or compensating control + POA&M โ€” and justify it against OT's safety, availability, and legacy-equipment constraints.

CSF Function Mapping

Take a documented incident (TRITON/TRISIS works well โ€” see the MITRE ATT&CK for ICS page) and map the organization's before/during/after actions onto the six CSF 2.0 functions.

Architecture Sketch

Students draw a reference OT network โ€” IT/OT DMZ, zones, boundary protection โ€” following Pillar 3's guidance, and justify each boundary they drew.

Cross-Framework Bridge

Take the same five overlay controls from the Tailoring Drill and identify which IEC 62443 foundational requirement each one most closely maps to โ€” reinforcing why Lesson 8 treats these frameworks as compatible, not competing.

09

Sources & Further Reading

This page is a teaching summary of a publicly available federal guidance document, not a reproduction of its full text. Section and appendix numbering, exact overlay content, and control counts should be verified against the current official SP 800-82 Rev. 3 publication before use in coursework โ€” per this course's own Safeguards policy on faculty review of generated content.