Frameworks / NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security / NISTSP82-2 NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security
OT Risk Assessment
NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security NISTSP82-2: OT Risk Assessment and Threat/Vulnerability Identification Conduct OT risk assessment per NIST SP 800-82 Rev 3 Chapter 4 (Risk Management) + Chapter 5 (OT Risk Analysis) tailored to OT-specific risk model. Apply NIST SP 800-30 Rev 1 methodology adjusted for OT considerations (a) threat sources include nation-state targeting critical infrastructure + insider with engineering access + supply chain compromise of OT components + commodity malware with OT-impact, (b) vulnerabilities span OT protocols (Modbus + DNP3 + IEC 61850 + PROFINET + EtherNet/IP + OPC) + legacy systems with extended lifecycles + safety system reliance on availability + physical-cyber coupling, (c) impact dimensions include operational disruption + safety incident + environmental release + equipment damage + production loss + cascading regulatory + reputational + public health/safety harm, (d) likelihood considers exposure (internet + IT-OT interconnection + remote access + vendor access) + active threat intelligence (CISA + ICS-CERT + sector ISAC). Conduct OT System Characterisation per Section 4.2 + OT Threat Assessment per Section 4.3 + OT Vulnerability Assessment per Section 4.4 + Risk Determination per Section 4.5. Document the OT risk register with explicit safety and availability impact alongside CIA.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 294 controls across 105 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions API1164-05 Network Segmentation and Zones API1164-07 Remote Access API1164-21 TSA Pipeline Security Directive Alignment API1164-22 Configuration management for OT systems API1164-23 Change management procedures API1164-24 Vulnerability assessment for critical systems IEC62443-05 Security policy for operational technology IEC62443-07 Personnel risk assessment IEC62443-21 Supply chain risk management for critical components IEC62443-22 Configuration management for OT systems IEC62443-23 Change management procedures IEC62443-24 Vulnerability assessment for critical systems AWWA-1.2 Risk Assessment AWWA-2.2 Authentication Mechanisms AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection AWWA-4.4 Audit Logging and Monitoring BSI-03 Multi-factor authentication requirements BSI-08 Cryptographic protection of data BSI-13 Risk assessment procedures BSI-15 Security categorization BSI-17 Continuous monitoring strategy ISO27019-05 Security policy for operational technology ISO27019-07 Personnel risk assessment ISO27019-22 Configuration management for OT systems ISO27019-23 Change management procedures ISO27019-24 Vulnerability assessment for critical systems ISO27043-13 Authentication and password management ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO21434-13 Authentication and password management ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management ISMSP-AC-03 Authentication Mechanisms ISMSP-MS-02 Risk Management ISMSP-PI-03 Third-Party Provision and Outsourcing ISMSP-SYS-02 Encryption Implementation ISMSP-SYS-04 Vulnerability Management CJIS-17 Risk Assessment CJIS-19 Supply Chain Risk Management CJIS-8 Media Protection CJIS-9 System and Communications Protection ISO27799-02 ePHI encryption at rest and in transit ISO27799-06 Security management process and risk analysis ISO27799-12 Unique user identification and authentication ISO27799-16 Transmission security and encryption 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 23837-1.7.3 Authentication and classical post-processing ISO23894-6.3 AI Risk Assessment ISO23894-6.3.1 AI Risk Identification ISO23894-6.3.3 AI Risk Evaluation ISO23894-A.6 AI System Security ISO27003-4.2 Understanding the needs and expectations of interested parties ISO27003-6.1 Actions to address risks and opportunities ISO27003-8.1 Operational planning and control ISO27003-8.2 Information security risk assessment 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats 29115-7.4 Level of Assurance 4 (LoA4) OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-3 A03:2025 Injection Including Cross-Site Scripting OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) OWASPTOP10-7 A07:2025 Identification and Authentication Failures CPS230-11 Identification, Assessment and Management of Operational Risk CPS230-27 Identification and Escalation of Incidents and Near Misses CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing ASD37-17 TLS encryption between email servers (Limited) ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity ISO-20400-7.3 Supplier selection ISO-20400-7.4 Contract management and review ISO-20400-7.5 Reviewing and learning 29134-1 Scope 29134-3 Terms and definitions 29134-9.1 PIA report structure OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OWASPLLM-4 Supply Chain and Vector/Embedding Weaknesses (LLM03 + LLM08) IM8-CLD.2 Cloud Security Controls IM8-SEC.4 Vulnerability Management IM8-TPM.4 Supply Chain Risk Management CH-FADP-13 Right to object and request blocking CH-FADP-21 Data protection impact assessments FADP-7 Data Protection Impact Assessment (Articles 9-10) AMLCTF-35 Identity Verification Standard AMLCTF-PartA-RiskAssess ML/TF Risk Assessment AEO-2 Demonstrated Compliance with Customs Requirements AEO-4 Financial Viability IS.D.OR.205 Information Security Risk Assessment IS.I.OR.205 Information Security Risk Assessment UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) Sapin2-Pillar3-Risk-Mapping Pillar 3 - Corruption Risk Mapping (Cartographie des Risques) Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A) ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain A.1 Point-of-Care Testing Additional Requirements ISO-15189-6.8 Externally provided products and services ISO28001-PC-03 Supply Chain Incident Reporting ISO28001-PC-04 Supply Chain Continuity Planning 27010-10.1 Cryptographic Protection 27010-15.1 Incident Management 27011-5.6 Supplier relationships and telecom supply chain 27011-8.3 Cryptography and key management 27400-6.1 Secure Device Design 27400-6.2 Device Identity and Authentication 27557-4.3 Individual impact consideration 27557-6.3 Privacy risk assessment BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition NZISM-1 NZISM Governance, Documentation, and Classification System NZISM-3 Personnel Security, Physical Security, and Cryptography NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP NGOB-3 API Security Standards, mTLS, and Encryption OWASPAPI-2 Broken Authentication and Token Management OWASPAPI-6 Security Misconfiguration and Secure API Design DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children 2.4.4 Hazard Analysis and Risk Assessment 2.7.2 Food Fraud Plan TURKEYKVKK-2 Information Notice and Data Subject Rights TURKEYKVKK-3 Special Categories and Sensitive Data CRM-1 AML/CFT Compliance CRM-4 Business Risk Assessment CPSC-CS.2 Authentication and Access Controls CPSC-RA.3 Lifecycle Risk Assessment USMCADIGITAL-2 Personal Information Protection and Consumer Protection USMCADIGITAL-4 Government Data, Cybersecurity, Interoperability VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VERMONTAICDA-4 Vermont AG Enforcement and Cure CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records APPI-A34 Request for Correction, Addition or Deletion AS9100D-8.4 Control of Externally Provided Processes, Products, Services 4.3.1 Risk Assessment and Impact Analysis ACQ.4 Supplier Monitoring Mat 03 Responsible Sourcing of Materials BB-DPA-20 Sections 50-60 - Registration and Responsibilities DSO-3 Data Access Management FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) 62351-9 Cyber security key management ISO-22313-8.2 Business impact analysis and risk assessment ISO22316-14 Supply chain continuity ISO-26000-6.6 Fair operating practices ISO-26262-3-7 Hazard analysis and risk assessment (HARA) ISO-41001-8.4 Control of outsourced processes and services ISO-50001-8.3 Procurement 27031-7.2 Resource Requirements 29147-5.11 Researcher Safe Harbour and Legal Posture ISO22317-14 Supply chain continuity ISO22318-14 Supply chain continuity STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NFPA1600-5.1 Risk Assessment NISTPF-5 Protect-P Access Control (PR.AC-P) NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment NJDPA-7 Data Protection Assessments and Processor Contracts AODACAN-2 Accessible Procurement of Goods, Services, Facilities EHDSREG-6 Phased Application and Enforcement RUSPD-2 Lawful Basis, Consent, Notice PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 GT-3 Supply Chain Compromise TEFCAREC-1 Common Agreement Conformance and Onboarding USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-2 Account Security Measures VIETNAMCYBER-4 Incident Reporting and Cooperation Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 294 it maps to, and the evidence behind each claim, over MCP and REST.