NIST SP 800-82
NIST SP 800-82, Guide to Operational Technology (OT) Security, is a freely available US NIST publication that explains how to secure industrial control and other OT systems while meeting their performance, reliability and safety needs.
NIST SP 800-82 is a special publication from the US National Institute of Standards and Technology that provides guidance on securing operational technology. Its third revision, published in 2023, is titled Guide to Operational Technology (OT) Security and broadened the earlier focus on industrial control systems to OT more generally, including building automation, transport and physical access control systems. It is freely available.
The guide explains how OT differs from IT, describes typical system architectures and threats, and sets out how to build an OT security programme, apply risk management and design defence-in-depth architectures with segmentation and DMZs. It includes an OT overlay of NIST SP 800-53 security controls, tailoring each control for OT environments. Although written for US organisations, it is used internationally alongside IEC 62443 and aligns with the NIST Cybersecurity Framework.
SP 800-82 is guidance rather than a certifiable standard, so organisations use it to shape programmes, select controls and justify compensating measures where OT constraints prevent standard IT practice. It is often referenced together with IEC 62443 for product and system requirements and with sector rules such as NERC CIP. Because NIST revises its publications, users should check for the current revision.
Key points
- Revision 3, published in 2023, broadened the scope from ICS to OT generally
- Covers OT risk management, programme development and security architecture
- Includes an OT overlay tailoring NIST SP 800-53 controls
- Guidance rather than a certifiable standard; often used alongside IEC 62443
Where AiVibe comes in
In AiVibe's AiAmbA AI Factory, the AiAmbA IoT edge layer keeps writes to machines deny-by-default and AI agents only propose changes that a trained operator confirms. AiVibe's security services include vulnerability assessment and penetration testing, and AiVibe is ISO/IEC 27001:2022 certified.
Related terms
- IEC 62443 (ISA/IEC 62443)OT & Industrial Cybersecurity
- Operational Technology (OT) SecurityOT & Industrial Cybersecurity
- Defence in DepthOT & Industrial Cybersecurity
- NERC CIP StandardsOT & Industrial Cybersecurity
- IT vs OT SecurityOT & Industrial Cybersecurity
- Industrial DMZ (IDMZ)OT & Industrial Cybersecurity