NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security
OT Config, Patch, Vulnerability, Malware

NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security NISTSP82-5: OT Configuration Management, Patching, Vulnerability Management, and Malware Protection

Operate OT configuration + patch + vulnerability + malware protection per NIST SP 800-82 Rev 3 Chapter 6 + Chapter 7. Configuration Management must (a) establish baseline configurations per asset class + version + maintain canonical golden image library, (b) enforce change control with engineering + safety + cybersecurity review for OT changes, (c) detect drift via authenticated configuration scanning + integrity monitoring, (d) align with IEC 62443-2-3 patch management for OT. OT Patch Management must (a) test patches in pre-production OT lab matching production OT topology before deployment, (b) coordinate with vendor support cycles + extended-life OEM commitments, (c) schedule deployment during planned outage windows aligned with operations + safety + regulatory permits, (d) document compensating controls where patching is infeasible (legacy systems + vendor-restricted environments + safety-certified equipment with patch lockdown). Vulnerability Management must (a) consume ICS-CERT advisories + vendor advisories + CISA KEV catalogue + sector ISAC feeds, (b) prioritise based on exposure + exploitability + mission impact + safety impact, (c) implement compensating controls where patching is infeasible (network segmentation + access restriction + monitoring intensification + insurance + spare equipment availability). Malware Protection in OT must (a) prefer application allowlisting over traditional signature antivirus, (b) deploy signature-based AV only where vendor-supported and tested, (c) use removable media controls with sandboxed transfer stations between IT and OT, (d) deploy file integrity monitoring on critical OT hosts.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 148 controls across 56 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 8 controls

  • API1164-08 Configuration Management
  • API1164-09 Patch and Vulnerability Management
  • API1164-11 Logging and Monitoring
  • API1164-12 Incident Response
  • API1164-14 Physical Security
  • API1164-22 Configuration management for OT systems
  • API1164-23 Change management procedures
  • API1164-24 Vulnerability assessment for critical systems
  • ASD37-04 User application hardening (Essential)
  • ASD37-06 Email content filtering (Excellent)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • FFIEC-07 Endpoint protection and detection
  • FFIEC-10 Secure configuration standards
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification

IEC 62443 · 5 controls

  • IEC62443-11 Security patch management for OT
  • IEC62443-12 Malware prevention for operational systems
  • IEC62443-14 System security hardening
  • IEC62443-22 Configuration management for OT systems
  • IEC62443-23 Change management procedures

ISO/IEC 27019:2024 · 5 controls

  • ISO27019-11 Security patch management for OT
  • ISO27019-12 Malware prevention for operational systems
  • ISO27019-14 System security hardening
  • ISO27019-22 Configuration management for OT systems
  • ISO27019-23 Change management procedures

NIST SP 1800-32 · 5 controls

  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • IEC62304-8.2 Change Control
  • IEC62304-9.4 Use Change Control Process
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied

NIST SP 800-53 Rev 5 · 4 controls

  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • AWWA-4.1 Malware Protection
  • AWWA-4.2 Patch Management
  • AWWA-4.3 Configuration Management

BSI IT-Grundschutz · 3 controls

  • BSI-23 Baseline configuration establishment
  • BSI-24 Configuration change control
  • BSI-26 System component inventory
  • CAT-D3-1 Preventative controls
  • CAT-D3-3 Corrective controls
  • CAT-D5-4 Resilience planning and testing

ISO/IEC 20000-1:2018 · 3 controls

  • ISO20000-03 Capacity and availability management
  • ISO20000-06 Change management processes
  • ISO20000-10 Configuration management

ITIL 4 · 3 controls

  • ITIL4-03 Capacity and availability management
  • ITIL4-06 Change management processes
  • ITIL4-10 Configuration management
  • NISTPF-6 Protect-P Data Security (PR.DS-P)
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-190 · 3 controls

  • IM8-DAT.2 Data Protection
  • IM8-DSS.2 Service Reliability Standards
  • IM8-RES.4 Resilience Testing
  • CPSC-STD.2 UL 5500 Remote Update Compliance
  • CPSC-SW.2 Software Update Safety Verification
  • CPSC-SW.3 Remote Update Security

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • CJIS-10 System and Information Integrity
  • CJIS-7 Configuration Management

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-1 Configuration Management Policy
  • FEDRAMP-CM-2 Baseline Configuration
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience
  • ISO-26262-8-7 Configuration management
  • ISO-26262-8-8 Change management

ISO/IEC 27031:2011 · 2 controls

  • 27031-8.1 Exercising and Testing
  • 27031-B High availability embedded systems

ISO/IEC 27400:2022 · 2 controls

  • 27400-6.3 Secure Update Mechanism
  • 27400-6.4 Default Configuration Security

ISO/IEC 30111:2019 · 2 controls

  • 30111-6.5 Remediation Strategy Selection
  • 30111-7.3 Quality assurance of remediation

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-8 A08:2025 Software and Data Integrity Failures
  • AS9100D-8.1 Operational Planning and Control
  • Clause 10 Change and configuration management
  • BS65000-RM-03 Leadership and Culture
  • CPG-5.A Vulnerability Disclosure Program

COBIT 2019 · 1 control

  • COBIT-BAI04 Managed availability and capacity
  • CA-ITSG33-SC-01 Security Control Catalogue
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

ISO 30401 · 1 control

  • ISO30401-18 Innovation and change management
  • ISO-25012-4.13 Availability

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ISO/IEC 27010:2015 · 1 control

  • 27010-12.2 Protection from malware

ISO/IEC 27011:2024 · 1 control

  • 27011-8.5 Vulnerability and malware management

ISO/IEC 27043:2015 · 1 control

  • ISO27043-22 Protection from malware

ISO/SAE 21434 · 1 control

  • ISO21434-22 Protection from malware
  • NZISM-5 Network Security, System Hardening, and Application Security
  • OWASPAPI-6 Security Misconfiguration and Secure API Design

OWASP ASVS · 1 control

  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP MASVS · 1 control

  • OWASPMASVS-6 MASVS-CODE: Code Quality, Build Settings, and Updates
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • KRCSAP-1 CSAP Certification Tiers (IaaS, SaaS, DaaS, AI)

South Korea ISMS-P · 1 control

  • ISMSP-SYS-01 System Hardening and Patch Management
  • CERT-1 RRA Certification to EPA

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 148 it maps to, and the evidence behind each claim, over MCP and REST.