Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Guide to Operational Technology (OT) Security: NIST Requests Comments on Draft SP 800-82r4

NIST has released the initial public draft of Special Publication (SP) 800-82r4 (Revision 4), Guide to Operational Technology (OT) Security, which provides guidelines for improving the security of operational technology (OT) systems while addressing thei

NIST has released the initial public draft of Special Publication (SP) 800-82r4 (Revision 4), Guide to Operational Technology (OT) Security, which provides guidelines for improving the security of operational technology (OT) systems while addressing their unique performance, reliability, and safety requirements.

OT encompasses a broad range of programmable systems or devices that interact with the physical environment (or manage devices that interact with the physical environment). These systems/devices detect or cause a direct change through the monitoring and/or control of devices, processes, and events. Examples include industrial control systems (ICS), building automation systems, transportation systems, physical access control systems, physical environment monitoring systems, and physical environment measurement systems. 

This fourth revision of SP 800-82 provides an overview of OT and typical system topologies, identifies common threats to organizational mission and business functions supported by OT, describes typical vulnerabilities in OT, and provides recommended security safeguards and countermeasures to manage the associated risks. 

Updates in this revision include:

  • Expanded introduction to OT sectors to include Building Automation and Control Systems (BACS), Water and Wastewater Systems (WWS), food and agriculture, freight rail, maritime vessels, and Industrial Internet of Things (IIoT) and cloud convergence
  • Restructured around the NIST Cybersecurity Framework (CSF) 2.0, including a reorganization of the previous risk management section to focus on the CSF Govern Function
  • Expanded discussion of how OT risk management aligns with broader enterprise risk management, as described in NIST IR 8286r1
  • Discussion of the adoption of the NIST Risk Management Framework (RMF) in Appendix F
  • Expanded guidelines for implementing OT security controls, including asset management and network monitoring and detection
  • Security architecture guidelines focused on protecting system management functions and applying zero trust principles

The comment period on this initial public draft is open through November 30, 2026. See the publication details for a copy of the draft and instructions for submitting comments.

NOTE: A call for patent claims is included in this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy – Inclusion of Patents in ITL Publications.

Released September 21, 2026
Was this page helpful?