MarketplaceCritical InfrastructureNIST SP 800-82 Rev. 3
Critical InfrastructureGuideline

NIST SP 800-82 Rev. 3

NIST Special Publication 800-02 Rev. 3 - Guide to Operational Technology (OT) Security

This document provides guidance on securing operational technology (OT) systems, which include programmable devices interacting with the physical environment. It addresses unique performance, reliability, and safety requirements, identifies threats, and recommends security measures.

Overview

NIST SP 800-82 Rev. 3 is a guide to securing operational technology (OT), such as industrial control systems, transportation systems, and building automation systems. It includes an overview of OT systems and their topologies, explores common threats and vulnerabilities, and provides detailed security countermeasures to mitigate risks. The standard emphasizes the need to balance security with the unique performance, reliability, and safety needs of OT systems. This revision, finalized in September 2023, supersedes Rev. 2 and includes updates reflecting advancements in OT and emerging security challenges. It serves industries that rely on OT systems and aims to improve their resilience against cyber threats.

Related in Critical Infrastructure

Critical InfrastructureRegulation

EASA Part-IS β€” European Union Aviation Safety Agency (EASA) - Part IS - Easy Access Rules for Information Security

The EASA Part-IS Regulation mandates information security measures within the aviation sector to address digital threats that impact safety. It provides a framework for managing risks, responding to incidents, and safeguarding aviation systems.

European Union β€’ EU β€’ vDecember 2025

View details
Critical InfrastructureGuideline

SMDDS β€” OWASP Secure Medical Devices Deployment Standard

The OWASP Secure Medical Devices Deployment Standard provides guidance for the secure deployment of medical devices within healthcare environments, addressing the rising threats such as botnets and malware targeting IoT devices. It emphasizes security measures across device purchasing, network security, interface controls, and incident handling.

OWASP

View details
Critical InfrastructureRegulation

DORA β€” Regulation (EU) 2022/2554 - Digital Operational Resilience Act

Regulation (EU) 2022/2554, known as DORA, establishes a unified framework for digital operational resilience in the European Union's financial sector. It aims to ensure financial entities can withstand, recover, and adapt to ICT-related disruptions while safeguarding the stability and integrity of the financial system.

European Parliament and Council of the European Union β€’ European Union

View details
Critical InfrastructureLaw

SOCIA 2018 β€” Security of Critical Infrastructure Act 2018

The Security of Critical Infrastructure Act 2018 (SOCIA) establishes a regulatory framework for managing national security risks to Australia’s critical infrastructure sectors. It introduces statutory obligations, reporting requirements, and oversight mechanisms for critical assets.

Australian Department of Home Affairs β€’ Australia β€’ vNo. 29, 2018

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks β€” automatically.

Book your strategy call