Edge Register
Standards ยท SP 800-82

NIST SP 800-82 Rev 3

Rendered when the buyer ticks "OT overlay (NIST SP 800-82 Rev 3)". The register cites 6 of its 48 clauses, behind 4 findings: regulated data at a site with nobody there, intermittent or no link, and no backup stated, plant with no segregation stated, remote access to plant, and on the duty rows of every site it reaches.

Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim. Source framework: NIST SP 800-82 Rev 3. What it attaches to a site: the SP 800-82 regime page.

Clauses cited

6 of 48
SP 800-82 OT-ARCH-1 Network Segmentation by Zones and Conduits

Segment OT networks into logical zones and conduits aligned with the Purdue model and IEC 62443, restricting traffic between zones via controlled conduits with documented data flows.

Evidence an auditor accepts: Zone and conduit diagram; Purdue level mapping; Conduit data flow matrix
Common gap: Flat OT network
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-PHYS-3 Tamper Detection and Response

Detect and respond to tampering of OT devices, cabinets, and network equipment through seals, sensors, alarms, and inspection procedures.

Evidence an auditor accepts: Tamper seal logs; Cabinet door alarm records; Inspection schedule and findings
Common gap: No tamper seals
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-RA-1 Secure Remote Access

Provide remote access to OT only via authenticated, encrypted, and brokered pathways such as jump hosts with multi-factor authentication, session recording, and time-bounded access.

Evidence an auditor accepts: Remote access policy; Jump host configuration; MFA enforcement records
Common gap: Direct VPN into OT
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-RA-2 Vendor Remote Access Controls

Manage vendor remote access through individually identified accounts, contractual obligations, just-in-time enablement, supervision, and full logging.

Evidence an auditor accepts: Vendor remote access agreements; Just-in-time enablement procedure; Supervision logs
Common gap: Always-on vendor tunnels
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-REC-3 Spare Parts and Cold Standby

Maintain spare PLCs, switches, servers, and media required for rapid replacement of failed or compromised OT components, with documented locations and integrity controls.

Evidence an auditor accepts: Spare parts inventory; Storage location records; Periodic test of cold spares
Common gap: Critical spares unavailable
Source framework: NIST SP 800-82 Rev 3
SP 800-82 OT-SECTOR-3 Distributed and Geographically Dispersed OT

Address security for geographically distributed OT (substations, pump stations, wellheads, remote terminal units) where physical access controls and connectivity options are constrained.

Evidence an auditor accepts: Remote site security standard; Communications security configuration (encrypted radio, cellular VPN); Site inspection records
Common gap: Unencrypted SCADA communications
Source framework: NIST SP 800-82 Rev 3

See which clauses your list engages

Paste the list and every site names the clauses behind it, filtered to the regimes that apply to you. Eight sites free, no account.

Build my edge register