Operate OT supply chain + asset lifecycle + physical security per NIST SP 800-82 Rev 3 Chapter 6 + Chapter 7. OT Supply Chain Security must (a) qualify OT vendors and suppliers per NIST SP 800-161 Supply Chain Risk Management tailored to OT (vendor cybersecurity maturity + product security incident response + vulnerability disclosure + secure development + provenance + SBOM availability + sub-component visibility), (b) embed cybersecurity requirements in procurement (RFPs + contracts + acceptance testing + warranty), (c) coordinate with vendor for product vulnerability handling + advisory consumption + patch availability + end-of-support planning, (d) document supply chain risks per asset and propagate through risk assessment. Secure System Lifecycle per Section 7 covering (a) Secure-by-design requirements for new OT systems, (b) commissioning security verification, (c) operational security maintenance, (d) extended-life cycle management including end-of-support compensating controls, (e) secure decommissioning and data sanitisation per NIST SP 800-88. Physical Security must (a) restrict physical access to OT assets via badge + visitor management + control rooms + cabinet locks + tamper-evident seals, (b) protect against environmental threats (temperature + humidity + flood + fire + electromagnetic interference) with monitoring + alerting, (c) integrate with safety + security operations + emergency response procedures.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.