Skip to main content

Reference

Frameworks and standards

Which framework answers which question, and how they fit together instead of competing.

Why should I care?

Frameworks are not a compliance chore: they give you a shared structure for scoping zones, assigning security levels and arguing for budget with evidence.

NIST SP 800-82 Rev. 3

NIST

Guide to Operational Technology Security, covering OT system topologies, threats, vulnerabilities and tailored countermeasures.

Who it is for

OT security practitioners, architects and programme owners in any sector.

What problem it solves

Applying security controls to environments where performance, reliability and safety requirements constrain conventional IT practice.

Relationship to OT

The most widely referenced general-purpose OT security guidance; a strong baseline for architecture and control selection.

Key concepts

  • OT-specific risk management
  • System topologies and architectures
  • Threat and vulnerability taxonomy for OT
  • Tailored control overlays
  • Safety and reliability considerations
NIST SP 800-82 Rev. 3

NIST Cybersecurity Framework 2.0

NIST

An outcome-based framework organised around Govern, Identify, Protect, Detect, Respond and Recover.

Who it is for

Organisations of any size needing a common language for cyber risk across IT and OT.

What problem it solves

Communicating security posture and priorities across technical and executive audiences.

Relationship to OT

Commonly used to structure an OT programme and report progress, with OT specifics supplied by SP 800-82 or IEC 62443.

Key concepts

  • Six functions
  • Categories and subcategories
  • Profiles and target states
  • Tiers
NIST Cybersecurity Framework

IEC 62443

IEC / ISA

A series of standards for industrial automation and control system security covering asset owners, integrators and product suppliers.

Who it is for

Asset owners, system integrators and equipment vendors.

What problem it solves

Defining security requirements and capability levels across the whole industrial supply chain.

Relationship to OT

Provides the zone/conduit model that underpins most modern OT segmentation designs and gives procurement a way to specify security capability.

Key concepts

  • Zones and conduits
  • Security levels (SL-T, SL-A, SL-C)
  • Foundational requirements
  • Maturity levels for processes
  • Component and system requirements
ISA/IEC 62443 series

CISA ICS Guidance

CISA

Advisories, alerts and recommended practices for industrial control systems, including defense-in-depth and incident response material.

Who it is for

Critical infrastructure operators, primarily but not exclusively in the United States.

What problem it solves

Timely vulnerability and threat information plus practical defensive recommendations.

Relationship to OT

The most practical day-to-day source for vulnerability intelligence and defensive recommendations in OT.

Key concepts

  • ICS advisories
  • Known Exploited Vulnerabilities catalog
  • Defense-in-depth recommended practices
  • Joint advisories with international partners
CISA Industrial Control Systems

MITRE ATT&CK for ICS

MITRE

A knowledge base of adversary tactics and techniques observed against industrial control systems.

Who it is for

Detection engineers, threat hunters and analysts.

What problem it solves

Providing a shared vocabulary for describing adversary behaviour and mapping detection coverage.

Relationship to OT

Used throughout this site to map hunts, incidents and protocol concerns to documented adversary behaviour.

Key concepts

  • Tactics and techniques
  • Assets
  • Mitigations
  • Software and groups
MITRE ATT&CK for ICS

NERC CIP

NERC

Mandatory reliability standards for cyber security of the bulk electric system in North America.

Who it is for

Registered entities operating bulk electric system assets in North America.

What problem it solves

Enforceable baseline security requirements for grid-critical cyber assets.

Relationship to OT

An example of sector-specific regulation; applicability depends entirely on your registration and jurisdiction.

Key concepts

  • BES Cyber System categorisation
  • Electronic Security Perimeters
  • Physical security
  • Configuration change management
  • Incident reporting and recovery plans
NERC CIP standards