NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security
OT Incident Response and Recovery

NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security NISTSP82-7: OT Incident Response, Forensics, Recovery, and Continuity

Operate OT incident response + forensics + recovery + continuity per NIST SP 800-82 Rev 3 Chapter 6 + Chapter 7 + integration with NIST SP 800-61 Rev 2 IR methodology. OT IR must address (a) OT-specific incident response plan with OT scenarios (ransomware on OT + malware on engineering workstation + unauthorised PLC change + safety system tamper + vendor compromise + insider sabotage + supply chain compromise), (b) IR team including IT cybersecurity + OT engineering + plant operations + safety + legal + communications + executive leadership, (c) containment strategies adapted to OT (network isolation + asset cordoning + manual operation fallback) considering safety constraints first, (d) preservation of forensic evidence with OT-specific challenges (PLC volatile memory + transient protocol traffic + historian time-series + safety system event logs), (e) recovery procedures including known-good backup restoration + safety system re-certification where applicable + regulator notification per sector requirements, (f) business continuity covering manual operation modes + alternate facility + parts inventory + vendor escalation, (g) post-incident lessons-learned with engineering + operations + safety + cybersecurity. Tabletop exercises annually + technical recovery test biennially + integrate with sector exercises (CISA + ISAC + regulator-led).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 294 controls across 125 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

ISO 22320:2018 · 6 controls

  • ISO-22320-5.1 General process requirements
  • ISO-22320-5.2 Incident management process
  • ISO-22320-5.3 Incident management structure (command)
  • ISO-22320-5.4 Roles and responsibilities
  • ISO-22320-B Annex B: Incident management plan structure
  • ISO-22320-C Annex C: Incident management task examples

API 1164 · 5 controls

  • API1164-12 Incident Response
  • API1164-13 Business Continuity and Recovery
  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)
  • FFIEC-05 Roles and responsibilities definition
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement

NIST SP 800-53 Rev 5 · 5 controls

ISO/IEC 27031:2011 · 4 controls

  • 27031-5.1 IRBC Policy
  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review

South Korea ISMS-P · 4 controls

  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-04 Vulnerability Management
  • ISMSP-SYS-05 Incident Response
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.7 Emergency and Incident Response
  • 4.4.8 Business Continuity and Recovery

BSI IT-Grundschutz · 3 controls

  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities
  • DA-1 Enterprise Data Architecture
  • DIQ-1 Data Integration and Interoperability
  • DIQ-2 Data Quality Management
  • IS.AR.215 Information Security Incident Response
  • IS.D.OR.225 External Reporting of Information Security Events
  • IS.I.OR.225 External Reporting
  • IEC62304-5.2 Software Requirements Analysis
  • IEC62304-5.3 Software Architectural Design
  • IEC62304-7.2 Risk Control Measures

IEC 62443 · 3 controls

  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents
  • ISO-15189-5.1 Legal entity
  • ISO-15189-5.4 Structure and authority
  • ISO-15189-6.7 Service agreements
  • ISO-19650-1-4 Information management concepts
  • ISO-19650-1-7 Common Data Environment (CDE) concept
  • ISO-19650-3-5.3 Trigger events for information exchange

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-1 Scope of AI Risk Management
  • ISO23894-3 AI-Specific Terminology
  • ISO23894-6.2 Scope, Context and Criteria

ISO/IEC 27004:2016 · 3 controls

  • 27004-3 Terms and definitions
  • 27004-A.2 Patching and Vulnerability Measures
  • 27004-B.1 Example measurement definitions

ISO/IEC 27011:2024 · 3 controls

  • 27011-1 Scope
  • 27011-3 Terms and definitions
  • 27011-8.6 Data protection and backup

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.2 Scope, context, and criteria for privacy

ISO/IEC 29100:2024 · 3 controls

  • 29100-1 Scope
  • 29100-3 Terms and definitions
  • 29100-4.1 Actors and roles

ISO/IEC 30111:2019 · 3 controls

  • 30111-3 Terms and definitions
  • 30111-5.1 Organizational policy
  • 30111-5.2 Vulnerability handling team
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.3 Emergency Response Operations
  • NFPA1600-6.4 Continuity and Recovery

NIST SP 1800-32 · 3 controls

NIST SP 800-190 · 3 controls

  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NISTSP34-4 Information System Contingency Plan (ISCP) Development
  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.3 Incident Response
  • IM8-RES.4 Resilience Testing

South Korea PIPA · 3 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • PIPA-Sensitive-Information-Unique-ID-Resident-Registration-Numbers-CCTV-Articles-23-24-25 Korea PIPA Sensitive Information + Unique ID + RRN + CCTV + Articles 23-25
  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • D.3 Backup and Recovery
  • 58.1 Scope
  • 58.3 Definitions

APPI · 2 controls

  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • AL-DPA-1 Scope and Definitions
  • AL-DPA-3 Lawful Basis for Processing
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training

Bahrain PDPL · 2 controls

  • BB-DPA-2 Section 2 - Interpretation
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-6 Configuration Settings
  • FEDRAMP-CP-9 System Backup
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • 60601-1.3 Terminology and definitions
  • 60601-1.4.1 General requirements
  • ISO-20400-4.2 Principles of sustainable procurement
  • ISO-20400-7.2 Integrating sustainability into specifications

ISO 22316 · 2 controls

  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • ISO28001-PI-01 Personnel Security Screening
  • ISO-41001-4.1 Understanding the organization and its context
  • ISO-41001-4.3 Determining the scope of the FM management system

ISO 56002 · 2 controls

  • ISO-56002-4.3 Determining the scope of the innovation management system
  • ISO-56002-8.3.4 Develop solutions
  • ISO8000-DQM-02 Data Quality Dimensions
  • ISO8000-MDG-03 Continuous Improvement
  • ISO-17025-5.1 Legal entity
  • ISO-17025-5.4 Personnel for the management system
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 27014:2020 · 2 controls

  • 27014-1 Scope
  • 27014-3 Terms and definitions

ISO/IEC 27043:2015 · 2 controls

  • ISO27043-04 Roles and responsibilities definition
  • ISO27043-23 Backup and recovery procedures

ISO/IEC 27400:2022 · 2 controls

  • 27400-3 Terms and definitions
  • 27400-6.5 Security monitoring and incident response

ISO/IEC 29147:2018 · 2 controls

  • 29147-3 Terms and definitions
  • 29147-9.2 Contact mechanisms and scope

ISO/SAE 21434 · 2 controls

  • ISO21434-04 Roles and responsibilities definition
  • ISO21434-23 Backup and recovery procedures

ISO/TS 22317:2021 · 2 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-12 Recovery strategy for critical activities

ISO/TS 22318:2021 · 2 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-6 Reasonable Data Security and Incident Response

OWASP ASVS · 2 controls

  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling

OWASP MASVS · 2 controls

  • OWASPMASVS-7 MASVS-RESILIENCE: Resilience Against Reverse Engineering
  • OWASPMASVS-8 MASVS-PRIVACY: Privacy and Data Protection

OWASP Top 10:2025 · 2 controls

  • ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication
  • ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • CYB-5 Cyber Incident Response Plan
  • USMTSA-2 Cybersecurity Assessment and CSO Designation
  • CFR211-A-3 Section 211.3 - Definitions
  • CPS230-13 Board Accountability for Operational Risk Management
  • AZ-DPA-2 Article 2 - Basic Concepts
  • CPG-6.B Supply Chain Incident Reporting

COBIT 2019 · 1 control

  • COBIT-BAI02 Managed requirements definition
  • CA-12 Deploys Through Policies and Procedures
  • CA-ITSG33-SC-01 Security Control Catalogue
  • CTDPA-1 Definitions
  • CAT-D5-1 Incident planning and strategy

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections
  • Sapin2-Pillar1-Code-of-Conduct Pillar 1 - Anti-Corruption Code of Conduct
  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor
  • IATA-IOSA-Section1-ORG-Organization-ManagementSystem-SMS IATA IOSA Section 1 - ORG Organization and Management System + Safety Management System (SMS) + Safety Policy + Hazard ID + Quality
  • 62351-2 Glossary of terms
  • ISO-14064-1-5.1 Organizational boundaries
  • ISO-26262-3-5 Item definition
  • ISO20000-11 Incident management

ISO/IEC 23837:2023 · 1 control

  • 23837-1.1 Scope

ISO/IEC 27003:2017 · 1 control

  • ISO27003-4.3 Determining the scope of the information security management system

ISO/IEC 27007:2020 · 1 control

  • 27007-5.2 Audit Programme Objectives

ISO/IEC 27010:2015 · 1 control

  • 27010-16.1 Continuity of Sharing
  • 27050-1.4 Terms and definitions
  • 29115-3 Terms and definitions

ISO/IEC 29134:2023 · 1 control

  • 29134-3 Terms and definitions

ITIL 4 · 1 control

  • ITIL4-11 Incident management
  • BIPA-SEC5-1 Biometric Identifier Definition
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold
  • OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards

PCI DSS 4.0 · 1 control

  • 2.2.2 2.2.2 Vendor default accounts managed
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • PSPF24-1 Security Culture, Governance, Risk Management
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)

SWIFT CSCF · 1 control

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)
  • SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VPSHR-3 Implementation Guidance and Reporting
  • W3CVCDM-1 Three-Party Ecosystem (Issuer, Holder, Verifier)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 294 it maps to, and the evidence behind each claim, over MCP and REST.