NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security
OT Access Control and IAM

NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security NISTSP82-4: OT Access Control, Identity, Authentication, and Remote Access

Implement OT access control per NIST SP 800-82 Rev 3 Chapter 6 (Security Architecture) + Chapter 7 (Applying the Cybersecurity Framework) covering identity + authentication + access management + remote access. Identity and access management must support (a) role-based access aligned to OT operational roles (operator + engineer + maintenance + vendor + reader-only + administrator), (b) multi-factor authentication for human users at every level above the field network (Level 2 and above) with hardware-token preferred for engineering and administrative roles, (c) emergency-bypass procedures documented and authorised that retain audit trail, (d) shared accounts only for legacy systems that genuinely cannot support individual identification + with compensating monitoring, (e) certificate-based machine-to-machine authentication where feasible, (f) directory federation between OT and IT only via dedicated identity broker not direct trust. Remote access (vendor + maintenance + remote engineering) must use (a) jump host or bastion architecture, (b) privileged access management with credential vaulting, (c) session recording for accountability and forensics, (d) just-in-time access with time-bounded approval workflow, (e) MFA at the jump host even when downstream targets cannot support MFA, (f) explicit network policy revoking access on session end. Authentication credentials and tokens specific to OT must be managed via OT-aware secrets management aligned with safety system requirements.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 182 controls across 73 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 11 controls

  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-2.2 Authentication Mechanisms
  • AWWA-2.4 Physical Access Controls
  • AWWA-4.4 Audit Logging and Monitoring

API 1164 · 4 controls

  • API1164-05 Network Segmentation and Zones
  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management

BSI IT-Grundschutz · 4 controls

  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

IEC 62443 · 4 controls

  • IEC62443-05 Security policy for operational technology
  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures

ISO 27799:2025 · 4 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-08 Information access management
  • ISO27799-12 Unique user identification and authentication
  • ISO27799-17 Facility access controls

ISO/IEC 27011:2024 · 4 controls

  • 27011-5.3 Segregation of duties
  • 27011-7.1 Physical security perimeters
  • 27011-7.3 Equipment protection
  • 27011-8.1 User Endpoint Devices

ISO/IEC 27019:2024 · 4 controls

  • ISO27019-05 Security policy for operational technology
  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures

ISO/IEC 27043:2015 · 4 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-13 Authentication and password management
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification

ISO/SAE 21434 · 4 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-13 Authentication and password management
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk

NIST SP 1800-32 · 4 controls

  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09)
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10)

OWASP Top 10:2025 · 4 controls

  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls
  • CAT-IRP-4 Organizational characteristics

ISO/IEC 27010:2015 · 3 controls

  • 27010-11.1 Physical Protection
  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources
  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-2 Broken Authentication and Token Management
  • OWASPAPI-3 Broken Object Property Level Authorization (BOPLA)
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

South Korea ISMS-P · 3 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-03 Authentication Mechanisms
  • ISMSP-AC-04 Network Access Control
  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735)

ISO/IEC 27400:2022 · 2 controls

  • 27400-5.2 IoT Risk Assessment
  • 27400-6.1 Secure Device Design
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-5 Protect-P Access Control (PR.AC-P)

NIST SP 800-190 · 2 controls

OWASP ASVS · 2 controls

  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • CYB-2 Account Security Measures
  • USMTSA-1 Facility Security Assessment and Plan
  • 58.43 Animal Care Facilities
  • AMLCTF-35 Identity Verification Standard

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV)

Bahrain PDPL · 1 control

  • CA-ITSG33-SC-01 Security Control Catalogue
  • CJIS-14 Physical Protection

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • 62351-8 Role-based access control (RBAC)
  • ISO28001-PS-01 Facility Security
  • ISO20000-15 Access management for services

ISO/IEC 23837:2023 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing

ITIL 4 · 1 control

  • ITIL4-15 Access management for services
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal

OWASP MASVS · 1 control

  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • EHDSREG-6 Phased Application and Enforcement
  • RUSPD-2 Lawful Basis, Consent, Notice

SWIFT CSCF · 1 control

South Korea PIPA · 1 control

  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • ACE-CR-4 Cargo Release Authorization
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 182 it maps to, and the evidence behind each claim, over MCP and REST.