Conduct OT risk assessment per NIST SP 800-82 Rev 3 Chapter 4 (Risk Management) + Chapter 5 (OT Risk Analysis) tailored to OT-specific risk model. Apply NIST SP 800-30 Rev 1 methodology adjusted for OT considerations (a) threat sources include nation-state targeting critical infrastructure + insider with engineering access + supply chain compromise of OT components + commodity malware with OT-impact, (b) vulnerabilities span OT protocols (Modbus + DNP3 + IEC 61850 + PROFINET + EtherNet/IP + OPC) + legacy systems with extended lifecycles + safety system reliance on availability + physical-cyber coupling, (c) impact dimensions include operational disruption + safety incident + environmental release + equipment damage + production loss + cascading regulatory + reputational + public health/safety harm, (d) likelihood considers exposure (internet + IT-OT interconnection + remote access + vendor access) + active threat intelligence (CISA + ICS-CERT + sector ISAC). Conduct OT System Characterisation per Section 4.2 + OT Threat Assessment per Section 4.3 + OT Vulnerability Assessment per Section 4.4 + Risk Determination per Section 4.5. Document the OT risk register with explicit safety and availability impact alongside CIA.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.