nisttrade-pressNewsThe Broadside1 min read

NIST opens comment period on OT security guide revision 4

SP 800-82r4 restructures around CSF 2.0 and adds sector-specific coverage for water, rail, maritime, building automation, and agriculture, a first for the OT guidance.


TL;DR

NIST released the initial public draft of SP 800-82r4 on September 21 and is accepting comments through November 30. The revision reorganizes OT security guidance around the CSF 2.0 framework and expands coverage to building automation, water and wastewater, food and agriculture, freight rail, maritime, and IIoT/cloud convergence. The Govern function now anchors the risk management section, and Appendix F discusses RMF adoption. Organizations operating OT in these sectors have until November 30 to tell NIST where the draft misses operational reality.

NIST opens comment period on OT security guide revision 4
Editorial illustration · drawn by The Broadside

The draft is the first update to SP 800-82 since CSF 2.0 released, and the structural shift reflects it. The risk management section has been reorganized around the CSF Govern function, and the remaining functions (Identify, Protect, Detect, Respond, and Recover) each get OT-specific treatment in section four. That's a meaningful change for organizations that map their OT controls to the CSF: the old SP 800-82 predates CSF 2.0's Govern function and didn't provide a corresponding anchor.

Alongside the CSF realignment, the draft brings several sectors into scope that hadn't appeared prominently in prior editions. Section two now walks through building automation and control systems, water and wastewater, food and agriculture, freight rail, and maritime vessels, each getting its own topology and threat discussion. An appendix overlays SP 800-53 controls against OT system needs.

The security architecture guidelines in section five emphasize network segmentation and separation, and the draft includes language on applying zero trust principles to OT environments. An expanded set of control implementation guidelines covers asset management and network monitoring and detection.

No publication date has been set for the final version, and NIST hasn't indicated a timeline for sector-specific control overlays. Comments go to sp800-82rev4@nist.gov with the subject "Comments on SP 800-82" through November 30.


Published ·Deep Fathom

NIST opens comment period on OT security guide revision 4 — The Broadside