NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security
OT Security Program Governance

NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security NISTSP82-1: OT Security Program Governance, Policy, Roles, and Safety-Security Integration

Establish an Operational Technology (OT) security program per NIST SP 800-82 Rev 3 Chapter 3 (OT Cybersecurity Program Development) and Chapter 4 (Risk Management). The program must (a) define OT scope distinct from IT (industrial control systems + SCADA + DCS + PLC + safety instrumented systems + building automation + transportation systems + medical devices where applicable), (b) document OT-specific risk tolerance recognising safety + reliability + availability priorities over confidentiality, (c) name accountable executives (CISO + Plant Manager + Safety Director + Operations Leadership) with documented decision authority, (d) integrate Safety and Security per Chapter 3 Section 3.7 covering shared assets + competing requirements + safety case integrity + cyber-physical interaction analysis, (e) align with NIST Cybersecurity Framework 2.0 OT profile + ISA/IEC 62443 + sectoral guidance (TSA Pipeline + CISA Water + FDA Medical Device + NRC Nuclear). Develop OT-specific policies covering acceptable use + change control + access control + remote access + incident response + business continuity + supply chain + safety system isolation. Establish OT security training and awareness for engineers + operators + maintenance + contractors + vendors.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.