United States

NIST SP 800-82 Rev 3

48 controls. 1 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

48 controls 1 frameworks share controls with it United States verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

NIST SP 800-82 Operational Technology (OT) Security Evidence & Implementation Kit

48 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

If you runShared controls
ISO 37001:20161measure it →

Every control

CodeControlAlso in
OT-ARCH-1Network Segmentation by Zones and Conduits0
OT-ARCH-2Industrial Demilitarised Zone (IDMZ)0
OT-ARCH-3Defense in Depth0
OT-ARCH-4Safety Instrumented System Isolation0
OT-ARCH-5Wireless Network Architecture0
OT-GOV-1OT Security Program Governance0
OT-GOV-2OT Risk Management Framework Alignment0
OT-GOV-3Safety and Security Integration0
OT-HOST-1OT Endpoint Hardening0
OT-HOST-2Application Allowlisting0
OT-HOST-3Anti-Malware for OT0
OT-HOST-4Patch Management for OT0
OT-HOST-5Removable Media Controls0
OT-HOST-6Configuration Change Management0
OT-IAM-1OT Account Management0
OT-IAM-2Authentication and Credential Management0
OT-IAM-3Least Privilege and Role Separation0
OT-IAM-4Physical Authentication for Field Devices0
OT-IR-1OT Incident Response Plan0
OT-IR-2OT Incident Detection and Triage0
OT-IR-3OT Incident Containment and Eradication0
OT-IR-4Forensics in OT Environments0
OT-IR-5Incident Exercises and Tabletops0
OT-MON-1OT Security Monitoring and Logging0
OT-MON-2Asset Inventory and Visibility0
OT-MON-3Anomaly and Behavioural Detection0
OT-MON-4Vulnerability Management for OT0
OT-NET-1OT Firewall Configuration0
OT-NET-2Industrial Protocol Filtering and Inspection0
OT-NET-3Network Intrusion Detection for OT0
OT-NET-4Boundary Protection and Egress Controls0
OT-NET-5OT Network Time Synchronisation0
OT-PHYS-1Physical Access Control to OT Assets0
OT-PHYS-2Environmental Controls0
OT-PHYS-3Tamper Detection and Response0
OT-RA-1Secure Remote Access0
OT-RA-2Vendor Remote Access Controls0
OT-REC-1OT Backup and Restoration0
OT-REC-2Contingency Planning0
OT-REC-3Spare Parts and Cold Standby0
OT-RM-1OT Risk Assessment Methodology0
OT-RM-2Supply Chain Risk Management0
OT-RM-3Awareness and Training for OT1
OT-RM-4Documentation and Information Protection0
OT-RM-5Continuous Monitoring of Controls0
OT-SECTOR-1Sector-Specific Overlay Application0
OT-SECTOR-2Building Automation System Security0
OT-SECTOR-3Distributed and Geographically Dispersed OT0

Tell me when NIST SP 800-82 Rev 3 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Crisis management plan
  • Team rotation roster
  • Exercise programme
  • trade continuity and resumption plan
  • role and responsibility matrix covering agencies and private sector participants
  • communication arrangements for a disruptive incident
  • Network architecture diagram
  • Firewall rule sets
  • Zone-conduit register
  • DMZ design

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for NIST SP 800-82 Rev 3, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition