Back to Frameworks

NIST SP 800-82 Rev 3

United States
10 domains
48 controls

NIST SP 800-82 Revision 3 Guide to Operational Technology (OT) Security.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (10)

Architecture

5 controls
Controls in the Architecture domain of NIST SP 800-82 Rev 35 controls
CodeTitle
OT-ARCH-1Network Segmentation by Zones and Conduits
OT-ARCH-2Industrial Demilitarised Zone (IDMZ)
OT-ARCH-3Defense in Depth
OT-ARCH-4Safety Instrumented System Isolation
OT-ARCH-5Wireless Network Architecture

Host Security

6 controls
Controls in the Host Security domain of NIST SP 800-82 Rev 36 controls
CodeTitle
OT-HOST-1OT Endpoint Hardening
OT-HOST-2Application Allowlisting
OT-HOST-3Anti-Malware for OT
OT-HOST-4Patch Management for OT
OT-HOST-5Removable Media Controls
OT-HOST-6Configuration Change Management

Identity & Access

6 controls
Controls in the Identity & Access domain of NIST SP 800-82 Rev 36 controls
CodeTitle
OT-IAM-1OT Account Management
OT-IAM-2Authentication and Credential Management
OT-IAM-3Least Privilege and Role Separation
OT-IAM-4Physical Authentication for Field Devices
OT-RA-1Secure Remote Access
OT-RA-2Vendor Remote Access Controls

Incident Response

5 controls
Controls in the Incident Response domain of NIST SP 800-82 Rev 35 controls
CodeTitle
OT-IR-1OT Incident Response Plan
OT-IR-2OT Incident Detection and Triage
OT-IR-3OT Incident Containment and Eradication
OT-IR-4Forensics in OT Environments
OT-IR-5Incident Exercises and Tabletops

Monitoring

4 controls
Controls in the Monitoring domain of NIST SP 800-82 Rev 34 controls
CodeTitle
OT-MON-1OT Security Monitoring and Logging
OT-MON-2Asset Inventory and Visibility
OT-MON-3Anomaly and Behavioural Detection
OT-MON-4Vulnerability Management for OT

Network Security

5 controls
Controls in the Network Security domain of NIST SP 800-82 Rev 35 controls
CodeTitle
OT-NET-1OT Firewall Configuration
OT-NET-2Industrial Protocol Filtering and Inspection
OT-NET-3Network Intrusion Detection for OT
OT-NET-4Boundary Protection and Egress Controls
OT-NET-5OT Network Time Synchronisation

Physical Security

3 controls
Controls in the Physical Security domain of NIST SP 800-82 Rev 33 controls
CodeTitle
OT-PHYS-1Physical Access Control to OT Assets
OT-PHYS-2Environmental Controls
OT-PHYS-3Tamper Detection and Response

Recovery

3 controls
Controls in the Recovery domain of NIST SP 800-82 Rev 33 controls
CodeTitle
OT-REC-1OT Backup and Restoration
OT-REC-2Contingency Planning
OT-REC-3Spare Parts and Cold Standby

Risk Management

8 controls
Controls in the Risk Management domain of NIST SP 800-82 Rev 38 controls
CodeTitle
OT-GOV-1OT Security Program Governance
OT-GOV-2OT Risk Management Framework Alignment
OT-GOV-3Safety and Security Integration
OT-RM-1OT Risk Assessment Methodology
OT-RM-2Supply Chain Risk Management
OT-RM-3Awareness and Training for OT
OT-RM-4Documentation and Information Protection
OT-RM-5Continuous Monitoring of Controls

Specific Sectors

3 controls
Controls in the Specific Sectors domain of NIST SP 800-82 Rev 33 controls
CodeTitle
OT-SECTOR-1Sector-Specific Overlay Application
OT-SECTOR-2Building Automation System Security
OT-SECTOR-3Distributed and Geographically Dispersed OT

Frequently Asked Questions

What is NIST SP 800-82 Rev 3?

NIST SP 800-82 Rev 3 is a compliance framework from United States with 10 domains and 48 controls. NIST SP 800-82 Revision 3 Guide to Operational Technology (OT) Security. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NIST SP 800-82 Rev 3 have?

NIST SP 800-82 Rev 3 has 48 controls organised across 10 domains. The largest domains are Risk Management (8 controls), Host Security (6 controls), Identity & Access (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NIST SP 800-82 Rev 3 map to?

NIST SP 800-82 Rev 3 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with NIST SP 800-82 Rev 3 compliance?

Start your NIST SP 800-82 Rev 3 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-82 Rev 3 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 48 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required