NIST SP 800-82 Rev 3, the OT overlay
Attaches to the sites that run plant: zones and conduits and the dispersed-OT guidance on every one, tamper detection where nobody is there, spares and cold standby where the link is intermittent, and the two remote-access controls where remote access is named. IEC 62443 is named beside it as a reference; its text is not quoted.
On the register, tick "OT overlay (NIST SP 800-82 Rev 3)" and these rows appear on the sites that run plant. Source framework: NIST SP 800-82 Rev 3, the OT overlay.
How the duties attach
| Reaches | The sites that run plant. |
|---|---|
| every site | OT-ARCH-1, OT-SECTOR-3 |
| site unattended | OT-PHYS-3 |
| site public | OT-PHYS-3 |
| site in a hostile place | OT-PHYS-3 |
| link intermittent | OT-REC-3 |
| no link | OT-REC-3 |
| remote access named | OT-RA-1, OT-RA-2 |
Named reference: IEC 62443
The plant classes name IEC 62443 beside the 800-82 rows as a reference. Its text is not held in the corpus in a verified form and is not quoted. Named references only: IEC 62443, industrial automation and control systems security (named on the plant classes; its text is not quoted).
The clauses, quoted
6 of 48 in the frameworkRequirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim.
SP 800-82 OT-ARCH-1 Network Segmentation by Zones and ConduitsSegment OT networks into logical zones and conduits aligned with the Purdue model and IEC 62443, restricting traffic between zones via controlled conduits with documented data flows.
Common gap: Flat OT network
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-PHYS-3 Tamper Detection and ResponseDetect and respond to tampering of OT devices, cabinets, and network equipment through seals, sensors, alarms, and inspection procedures.
Common gap: No tamper seals
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-RA-1 Secure Remote AccessProvide remote access to OT only via authenticated, encrypted, and brokered pathways such as jump hosts with multi-factor authentication, session recording, and time-bounded access.
Common gap: Direct VPN into OT
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-RA-2 Vendor Remote Access ControlsManage vendor remote access through individually identified accounts, contractual obligations, just-in-time enablement, supervision, and full logging.
Common gap: Always-on vendor tunnels
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-REC-3 Spare Parts and Cold StandbyMaintain spare PLCs, switches, servers, and media required for rapid replacement of failed or compromised OT components, with documented locations and integrity controls.
Common gap: Critical spares unavailable
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-SECTOR-3 Distributed and Geographically Dispersed OTAddress security for geographically distributed OT (substations, pump stations, wellheads, remote terminal units) where physical access controls and connectivity options are constrained.
Common gap: Unencrypted SCADA communications
Source framework: NIST SP 800-82 Rev 3
See what it attaches to your list
Paste the site list, tick the regime, and every site it reaches carries these rows by its exposure, link, data and plant. Eight sites free, no account.
Build my edge register