Quick Facts
Foundations
How to Use This Guide
- 1
Skim the Quick Facts panel first. The scope line โ "all OT," not just ICS โ is the single fact that most separates Rev. 3 from everything that came before it.
- 2
Read Section 03 before the structure itself. Seeing how SP 800-82 differs from IEC 62443, ATT&CK for ICS, and CIP-008 makes its risk-management framing easier to place.
- 3
Work through Section 04's four pillar cards in order โ Understand โ Manage Risk โ Architect โ Align. They follow the guide's own chapter progression from OT fundamentals through to the SP 800-53 overlays.
- 4
Treat Section 05 as a lookup, not a read-through. Terms like "overlay" and "tailoring" get reused constantly once you reach Section 04.3 โ come back here when one is unfamiliar.
- 5
If you're prepping to teach, start at Section 08. The Overlay Tailoring Drill is the exercise most students find clarifies the whole guide at once.
Positioning: SP 800-82 vs. the Other Core Frameworks
IEC 62443 is a standalone, certifiable design standard. ATT&CK for ICS is a descriptive threat-intelligence knowledge base. CIP-008 is a mandatory sector regulation. SP 800-82 sits in a fourth position: voluntary federal guidance that pulls an organization's OT risk management into the same ecosystem as its IT risk management.
| Attribute | NIST SP 800-82 Rev. 3 | IEC 62443 / ATT&CK for ICS / CIP-008 |
|---|---|---|
| Type | Federal risk-management guidance | Certifiable design standard, threat-intel knowledge base, or mandatory sector regulation |
| Origin / Authority | NIST, a U.S. federal standards body | ISA/IEC standards body, MITRE (federally funded R&D), NERC (the ERO, under FERC) |
| Primary Question | "How do I manage OT risk using the same control catalog and process my IT team already uses?" | "How should this be designed?", "What has been done to systems like this?", or "What must I legally report?" |
| Enforcement | Required for U.S. federal agencies via FISMA/RMF; voluntary elsewhere | Certification (62443), none (ATT&CK for ICS), or legal penalty (CIP-008) |
| Typical Pairing | Supplies the risk-management and control-baseline layer that the others plug into | 62443 supplies the zones/conduits vocabulary; ATT&CK for ICS supplies the threat data; CIP-008 supplies the reporting obligation once a risk becomes an incident |
Structure & Overlays
SP 800-82 Rev. 3 reads as four pillars building on each other: understand what OT actually is, manage risk against it, architect a defense, and align that defense to the broader NIST control ecosystem. The colors below deliberately reuse this site's existing strand colors โ Understand borrows the orange used for "Foundations," Manage Risk borrows the purple used for "Frameworks," Architect borrows the blue used for "Protocols," and Align borrows the green used for "Operations."
OT Overview
OT Risk Management
Cybersecurity Architecture
Frameworks & Overlays
Pillar 1 โ Understand OT
Pillar 2 โ Manage Risk
Pillar 3 โ Architect Defense
Pillar 4 โ Align to Frameworks & Controls
Definitions & Scope
These terms come directly from the broader NIST risk-management vocabulary that SP 800-82 inherits and tailors.
Operational Technology (OT)
Hardware and software that detects or causes changes in physical processes through direct monitoring or control โ the Rev. 3 scope, wider than "ICS."
Industrial Control System (ICS)
The classic subset of OT โ SCADA, DCS, and PLC-based systems controlling industrial processes โ that Rev. 1 and Rev. 2 focused on exclusively.
Overlay
A pre-tailored, specialized set of security controls, control enhancements, and supplemental guidance for a particular type of system or environment โ here, OT at a given impact tier.
Security Control Baseline
The starting set of controls associated with a system's impact level (Low, Moderate, High) before any further tailoring is applied.
Tailoring
The documented process of adjusting a control baseline โ adding, removing, or modifying controls โ to fit an actual environment's constraints.
Compensating Control
An alternative safeguard used when the originally specified control can't be implemented as written โ the standard response to OT's patch and legacy constraints.
Risk Management Framework (RMF)
NIST SP 800-37's overall process โ categorize, select, implement, assess, authorize, monitor โ that SP 800-82's OT risk chapter follows and tailors.
System Security Plan (SSP)
The document that records which controls apply to a system and how they're implemented โ where an OT overlay's selections ultimately get written down.
Related NIST Resources
SP 800-82 doesn't stand alone โ it's one node in NIST's much larger risk-management publication set, and it borrows structure and vocabulary from several others.
| Resource | Focus | How It Connects to SP 800-82 |
|---|---|---|
| SP 800-53 Rev. 5 | The base security & privacy control catalog | The catalog that SP 800-82's OT overlays tailor for Low/Moderate/High-impact OT |
| NIST Cybersecurity Framework 2.0 | Outcome-based function structure | The Govern/Identify/Protect/Detect/Respond/Recover functions SP 800-82's risk activities are mapped onto |
| SP 800-37 | Risk Management Framework (RMF) | The overall categorize-select-implement-assess-authorize-monitor process SP 800-82's OT risk chapter follows |
| SP 800-30 | Guide for Conducting Risk Assessments | The general risk-assessment methodology that SP 800-82 tailors for OT-specific threat sources and impact |
| NIST SP 1800 Series | NCCoE practice guides | Sector-specific, hands-on implementation examples that show SP 800-82 guidance applied to real reference architectures |
Adoption & Practical Use
SP 800-82 occupies a middle ground between CIP-008's legal mandate and ATT&CK for ICS's total lack of enforcement: it is required for U.S. federal agencies through FISMA-driven RMF processes, and voluntarily โ but very widely โ adopted everywhere else.
Federal Agencies
Required as the OT-specific control reference within FISMA-driven Risk Management Framework processes for federal OT-adjacent systems.
Critical Infrastructure Operators
Adopted voluntarily as a free, vendor-neutral OT security reference โ often the first document a new OT security hire is handed.
Auditors & Assessors
Used as a control-mapping reference when assessing an OT environment against the SP 800-53 catalog it tailors.
Vendors & Integrators
Cited directly in RFPs and contracts as the expected control baseline for a delivered OT system, especially in the public sector.
๐ Teaching Note
Anchor lesson: Lesson 8 (Frameworks for OT Security) and Lesson 9 (Governance, Risk & Compliance). For the "pick one spine instead of four" discussion in Lesson 8, have students open the OT overlay appendix and select five controls to map against a fictional plant; in Lesson 9, have them write POA&M entries for a control that isn't feasible.
Classroom Uses
Overlay Tailoring Drill
Give students five controls from an OT overlay baseline and a fictional plant scenario. For each, they decide: implement as-is, tailor, or compensating control + POA&M โ and justify it against OT's safety, availability, and legacy-equipment constraints.
CSF Function Mapping
Take a documented incident (TRITON/TRISIS works well โ see the MITRE ATT&CK for ICS page) and map the organization's before/during/after actions onto the six CSF 2.0 functions.
Architecture Sketch
Students draw a reference OT network โ IT/OT DMZ, zones, boundary protection โ following Pillar 3's guidance, and justify each boundary they drew.
Cross-Framework Bridge
Take the same five overlay controls from the Tailoring Drill and identify which IEC 62443 foundational requirement each one most closely maps to โ reinforcing why Lesson 8 treats these frameworks as compatible, not competing.
Sources & Further Reading
- NIST SP 800-82 Rev. 3 (Official Publication)Full text, supplemental material, and errata from NIST's Computer Security Resource Center
- NIST Cybersecurity FrameworkThe CSF functions SP 800-82's OT risk guidance is mapped against
- NIST SP 800-53 Rev. 5The base control catalog that SP 800-82's OT overlays tailor
- NIST SP 800-37 Rev. 2 โ Risk Management FrameworkThe overall risk process SP 800-82's OT risk chapter follows
This page is a teaching summary of a publicly available federal guidance document, not a reproduction of its full text. Section and appendix numbering, exact overlay content, and control counts should be verified against the current official SP 800-82 Rev. 3 publication before use in coursework โ per this course's own Safeguards policy on faculty review of generated content.