NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security
OT Incident Response and Recovery

NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security 7: OT Incident Response, Forensics, Recovery, and Continuity

Operate OT incident response + forensics + recovery + continuity per NIST SP 800-82 Rev 3 Chapter 6 + Chapter 7 + integration with NIST SP 800-61 Rev 2 IR methodology. OT IR must address (a) OT-specific incident response plan with OT scenarios (ransomware on OT + malware on engineering workstation + unauthorised PLC change + safety system tamper + vendor compromise + insider sabotage + supply chain compromise), (b) IR team including IT cybersecurity + OT engineering + plant operations + safety + legal + communications + executive leadership, (c) containment strategies adapted to OT (network isolation + asset cordoning + manual operation fallback) considering safety constraints first, (d) preservation of forensic evidence with OT-specific challenges (PLC volatile memory + transient protocol traffic + historian time-series + safety system event logs), (e) recovery procedures including known-good backup restoration + safety system re-certification where applicable + regulator notification per sector requirements, (f) business continuity covering manual operation modes + alternate facility + parts inventory + vendor escalation, (g) post-incident lessons-learned with engineering + operations + safety + cybersecurity. Tabletop exercises annually + technical recovery test biennially + integrate with sector exercises (CISA + ISAC + regulator-led).

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.