NIST SP 800-82 Rev 3
NIST SP 800-82 Revision 3 Guide to Operational Technology (OT) Security.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (10)
Architecture
| Code | Title |
|---|---|
| OT-ARCH-1 | Network Segmentation by Zones and Conduits |
| OT-ARCH-2 | Industrial Demilitarised Zone (IDMZ) |
| OT-ARCH-3 | Defense in Depth |
| OT-ARCH-4 | Safety Instrumented System Isolation |
| OT-ARCH-5 | Wireless Network Architecture |
Host Security
| Code | Title |
|---|---|
| OT-HOST-1 | OT Endpoint Hardening |
| OT-HOST-2 | Application Allowlisting |
| OT-HOST-3 | Anti-Malware for OT |
| OT-HOST-4 | Patch Management for OT |
| OT-HOST-5 | Removable Media Controls |
| OT-HOST-6 | Configuration Change Management |
Identity & Access
| Code | Title |
|---|---|
| OT-IAM-1 | OT Account Management |
| OT-IAM-2 | Authentication and Credential Management |
| OT-IAM-3 | Least Privilege and Role Separation |
| OT-IAM-4 | Physical Authentication for Field Devices |
| OT-RA-1 | Secure Remote Access |
| OT-RA-2 | Vendor Remote Access Controls |
Incident Response
| Code | Title |
|---|---|
| OT-IR-1 | OT Incident Response Plan |
| OT-IR-2 | OT Incident Detection and Triage |
| OT-IR-3 | OT Incident Containment and Eradication |
| OT-IR-4 | Forensics in OT Environments |
| OT-IR-5 | Incident Exercises and Tabletops |
Monitoring
| Code | Title |
|---|---|
| OT-MON-1 | OT Security Monitoring and Logging |
| OT-MON-2 | Asset Inventory and Visibility |
| OT-MON-3 | Anomaly and Behavioural Detection |
| OT-MON-4 | Vulnerability Management for OT |
Network Security
| Code | Title |
|---|---|
| OT-NET-1 | OT Firewall Configuration |
| OT-NET-2 | Industrial Protocol Filtering and Inspection |
| OT-NET-3 | Network Intrusion Detection for OT |
| OT-NET-4 | Boundary Protection and Egress Controls |
| OT-NET-5 | OT Network Time Synchronisation |
Physical Security
| Code | Title |
|---|---|
| OT-PHYS-1 | Physical Access Control to OT Assets |
| OT-PHYS-2 | Environmental Controls |
| OT-PHYS-3 | Tamper Detection and Response |
Recovery
| Code | Title |
|---|---|
| OT-REC-1 | OT Backup and Restoration |
| OT-REC-2 | Contingency Planning |
| OT-REC-3 | Spare Parts and Cold Standby |
Risk Management
| Code | Title |
|---|---|
| OT-GOV-1 | OT Security Program Governance |
| OT-GOV-2 | OT Risk Management Framework Alignment |
| OT-GOV-3 | Safety and Security Integration |
| OT-RM-1 | OT Risk Assessment Methodology |
| OT-RM-2 | Supply Chain Risk Management |
| OT-RM-3 | Awareness and Training for OT |
| OT-RM-4 | Documentation and Information Protection |
| OT-RM-5 | Continuous Monitoring of Controls |
Specific Sectors
| Code | Title |
|---|---|
| OT-SECTOR-1 | Sector-Specific Overlay Application |
| OT-SECTOR-2 | Building Automation System Security |
| OT-SECTOR-3 | Distributed and Geographically Dispersed OT |
Frequently Asked Questions
What is NIST SP 800-82 Rev 3?
NIST SP 800-82 Rev 3 is a compliance framework from United States with 10 domains and 48 controls. NIST SP 800-82 Revision 3 Guide to Operational Technology (OT) Security. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NIST SP 800-82 Rev 3 have?
NIST SP 800-82 Rev 3 has 48 controls organised across 10 domains. The largest domains are Risk Management (8 controls), Host Security (6 controls), Identity & Access (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NIST SP 800-82 Rev 3 map to?
NIST SP 800-82 Rev 3 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I get started with NIST SP 800-82 Rev 3 compliance?
Start your NIST SP 800-82 Rev 3 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-82 Rev 3 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 48 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.
Get Started Free →Free forever — no credit card required