Edge Register
Regimes ยท SP 800-82

NIST SP 800-82 Rev 3, the OT overlay

Attaches to the sites that run plant: zones and conduits and the dispersed-OT guidance on every one, tamper detection where nobody is there, spares and cold standby where the link is intermittent, and the two remote-access controls where remote access is named. IEC 62443 is named beside it as a reference; its text is not quoted.

On the register, tick "OT overlay (NIST SP 800-82 Rev 3)" and these rows appear on the sites that run plant. Source framework: NIST SP 800-82 Rev 3, the OT overlay.

How the duties attach

ReachesThe sites that run plant.
every siteOT-ARCH-1, OT-SECTOR-3
site unattendedOT-PHYS-3
site publicOT-PHYS-3
site in a hostile placeOT-PHYS-3
link intermittentOT-REC-3
no linkOT-REC-3
remote access namedOT-RA-1, OT-RA-2

Named reference: IEC 62443

The plant classes name IEC 62443 beside the 800-82 rows as a reference. Its text is not held in the corpus in a verified form and is not quoted. Named references only: IEC 62443, industrial automation and control systems security (named on the plant classes; its text is not quoted).

The clauses, quoted

6 of 48 in the framework

Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim.

SP 800-82 OT-ARCH-1 Network Segmentation by Zones and Conduits

Segment OT networks into logical zones and conduits aligned with the Purdue model and IEC 62443, restricting traffic between zones via controlled conduits with documented data flows.

Evidence an auditor accepts: Zone and conduit diagram; Purdue level mapping; Conduit data flow matrix
Common gap: Flat OT network
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-PHYS-3 Tamper Detection and Response

Detect and respond to tampering of OT devices, cabinets, and network equipment through seals, sensors, alarms, and inspection procedures.

Evidence an auditor accepts: Tamper seal logs; Cabinet door alarm records; Inspection schedule and findings
Common gap: No tamper seals
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-RA-1 Secure Remote Access

Provide remote access to OT only via authenticated, encrypted, and brokered pathways such as jump hosts with multi-factor authentication, session recording, and time-bounded access.

Evidence an auditor accepts: Remote access policy; Jump host configuration; MFA enforcement records
Common gap: Direct VPN into OT
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-RA-2 Vendor Remote Access Controls

Manage vendor remote access through individually identified accounts, contractual obligations, just-in-time enablement, supervision, and full logging.

Evidence an auditor accepts: Vendor remote access agreements; Just-in-time enablement procedure; Supervision logs
Common gap: Always-on vendor tunnels
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-REC-3 Spare Parts and Cold Standby

Maintain spare PLCs, switches, servers, and media required for rapid replacement of failed or compromised OT components, with documented locations and integrity controls.

Evidence an auditor accepts: Spare parts inventory; Storage location records; Periodic test of cold spares
Common gap: Critical spares unavailable
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-SECTOR-3 Distributed and Geographically Dispersed OT

Address security for geographically distributed OT (substations, pump stations, wellheads, remote terminal units) where physical access controls and connectivity options are constrained.

Evidence an auditor accepts: Remote site security standard; Communications security configuration (encrypted radio, cellular VPN); Site inspection records
Common gap: Unencrypted SCADA communications
Source framework: NIST SP 800-82 Rev 3

See what it attaches to your list

Paste the site list, tick the regime, and every site it reaches carries these rows by its exposure, link, data and plant. Eight sites free, no account.

Build my edge register