Protect critical systems and data with layers combining people, procedures and technology to raise detection chances, use resources well and isolate systems; connected OT should have more than one technical or procedural measure, since firewalls alone do not stop insiders. The layers include physical security under the SSP, network protection and segmentation, intrusion detection, firewalls, periodic vulnerability scanning, patching and whitelisting, user and access controls, change and configuration management, removable media and password procedures, awareness and familiarity with procedures including incident response. For integration, consider zero trust or trust boundary models and, for large networks, threat modelling, applying measures across all integrated systems (defence in breadth) so a weakness in one cannot bypass another; prioritise the controls giving most benefit.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.